Attackers are exploiting a code injection flaw in on-premises Microsoft SharePoint Server and an SSH session-handling bug in MikroTik RouterOS, according to the US Cybersecurity and Infrastructure Security Agency, which added both to its Known Exploited Vulnerabilities (KEV) catalog on 25 September. Federal civilian agencies have until 28 September to act, a three-day window.
The two flaws land on very different equipment: an on-premises document platform that an attacker with any valid account can reach, and network-edge routers whose SSH service is the direct target of the RouterOS flaws.
What CISA has put on record
CVE-2026-65660, SharePoint Server. CISA lists this as a code injection weakness (CWE-94) through which an attacker who already holds some level of access can run code on the server over the network. The Microsoft-supplied CVSS 3.1 base score recorded in the NVD is 8.8, reflecting low attack complexity, low privileges required and no user interaction. CISA’s own SSVC assessment, attached to the record on the day of the KEV listing, marks exploitation as active and the technical impact as total, meaning a successful attacker controls the affected system. The NVD configuration data covers SharePoint Server Subscription Edition builds before 16.0.19725.20522, plus SharePoint Server 2016 Enterprise and SharePoint Server 2019. The CVE was published on 11 August with a Microsoft advisory, so this is not a new disclosure; the KEV listing confirms attackers are exploiting it, which puts any server still unpatched six weeks on at direct risk.
CISA also flagged this entry for forensic triage. In practice that means patching alone does not close the case: under Binding Operational Directive 26-04, agencies must also check whether the server was compromised before the update went on.
CVE-2026-67279, MikroTik RouterOS. According to the NVD record, the RouterOS SSH service fails to enforce authentication after a client-initiated key renegotiation, so a client that never logged in can still have a command run by the router. On affected builds this lets an unauthenticated party create, overwrite and rebuild files in the router’s managed file area, including support files that hold configuration and diagnostic data. The score supplied by the assigning CNA is a CVSS 4.0 base of 6.9, rated medium.
That score understates the risk. CISA’s catalog entry notes that this bug can be combined with CVE-2026-86060, a RouterOS SSH login flaw that lets an attacker alter the router’s internal policy mask and escalate privileges, so that CVE-2026-86060 can be exploited without credentials. CVE-2026-86060 carries a CVSS 4.0 score of 9.2 and has been in the KEV catalog since 10 September. The newly listed flaw is the piece that removes the need for a valid session, so the combination amounts to unauthenticated takeover of an exposed router. Fixed releases are 6.49.21 and 7.23.4 on the long-term branches and 7.24.2 on the stable branch.
Gaps in the public record
Neither entry names a threat actor, a campaign, or the sectors being targeted, and CISA gives no indication of how widespread the activity is. Ransomware use is recorded as unknown for both, which is not the same as ruled out. No indicators of compromise accompanied the listing. Unlike the SharePoint entry, the RouterOS entry is not flagged for forensic triage, though the chained CVE-2026-86060 path gives little reason to assume an exposed, unpatched router is clean. CISA did flag CVE-2026-86060 itself for forensic triage. Exploitation status in this article is CISA’s finding; Quietlytic has not independently observed it.
Who is exposed
For SharePoint, the exposure is any organisation still running an on-premises farm on the versions above. SharePoint Online is not listed in the NVD configuration data. Because exploitation requires some level of authenticated access, internet-facing farms with broad external sharing or contractor accounts deserve the closest look, as do farms where a phished employee account could reach the server.
For RouterOS, the exposure is any device on a build older than the fixed releases with its SSH service reachable by an untrusted network. Managed service providers and ISPs that operate fleets of MikroTik equipment should treat this as a fleet-wide problem rather than a device-by-device one, since a single unpatched image usually means many unpatched units.
Priorities for defenders
- Close SSH on MikroTik devices first. If RouterOS SSH is reachable from the internet, restrict it to management addresses through the router’s IP service settings or firewall rules today. This blunts both RouterOS flaws while upgrades are scheduled.
- Upgrade RouterOS to 6.49.21, 7.23.4 or 7.24.2 or later. Confirm the running version on every device afterwards; an upgrade that did not complete leaves the device exactly as exposed as before.
- Check routers for tampering. Review configuration exports against a known-good copy and look for unexpected users, scheduler entries, scripts and files. A router that was reachable while vulnerable should be treated as suspect until checked.
- Patch SharePoint Server and verify the build. Apply the Microsoft update listed in the vendor advisory for CVE-2026-65660 and confirm the farm reports a build at or above the fixed level on every server in the farm.
- Hunt on SharePoint servers before closing the ticket. Following CISA’s forensic triage flag, review web server and SharePoint logs since mid-August for unusual requests from authenticated accounts, look for unfamiliar files in web directories, and check for new or changed site collection administrators. Rotate credentials for any service accounts on a server that shows signs of access.
- Tighten SharePoint access paths. Limit external exposure where it is not required and review which external and guest accounts can reach the farm.
Organisations outside the US federal government are not bound by the 28 September deadline, but the KEV catalog remains one of the clearest public signals separating flaws attackers are using from those they might. One of these entries completes an already-exploited router takeover chain, and the other gives a foothold on a document platform that many organisations treat as a trusted internal system. Both belong ahead of the ordinary patch queue.
Source: Cybersecurity and Infrastructure Security Agency (CISA)