Skip to main content
QUIETLYTIC
Active exploitation

CISA confirms exploitation of SharePoint and MikroTik RouterOS flaws

CISA added a SharePoint code injection flaw and a MikroTik RouterOS SSH bug that completes a known router takeover chain to KEV, with a 28 September deadline.

Category
Active exploitation
Severity
High
CVEs
CVE-2026-65660, CVE-2026-67279

Attackers are exploiting a code injection flaw in on-premises Microsoft SharePoint Server and an SSH session-handling bug in MikroTik RouterOS, according to the US Cybersecurity and Infrastructure Security Agency, which added both to its Known Exploited Vulnerabilities (KEV) catalog on 25 September. Federal civilian agencies have until 28 September to act, a three-day window.

The two flaws land on very different equipment: an on-premises document platform that an attacker with any valid account can reach, and network-edge routers whose SSH service is the direct target of the RouterOS flaws.

What CISA has put on record

CVE-2026-65660, SharePoint Server. CISA lists this as a code injection weakness (CWE-94) through which an attacker who already holds some level of access can run code on the server over the network. The Microsoft-supplied CVSS 3.1 base score recorded in the NVD is 8.8, reflecting low attack complexity, low privileges required and no user interaction. CISA’s own SSVC assessment, attached to the record on the day of the KEV listing, marks exploitation as active and the technical impact as total, meaning a successful attacker controls the affected system. The NVD configuration data covers SharePoint Server Subscription Edition builds before 16.0.19725.20522, plus SharePoint Server 2016 Enterprise and SharePoint Server 2019. The CVE was published on 11 August with a Microsoft advisory, so this is not a new disclosure; the KEV listing confirms attackers are exploiting it, which puts any server still unpatched six weeks on at direct risk.

CISA also flagged this entry for forensic triage. In practice that means patching alone does not close the case: under Binding Operational Directive 26-04, agencies must also check whether the server was compromised before the update went on.

CVE-2026-67279, MikroTik RouterOS. According to the NVD record, the RouterOS SSH service fails to enforce authentication after a client-initiated key renegotiation, so a client that never logged in can still have a command run by the router. On affected builds this lets an unauthenticated party create, overwrite and rebuild files in the router’s managed file area, including support files that hold configuration and diagnostic data. The score supplied by the assigning CNA is a CVSS 4.0 base of 6.9, rated medium.

That score understates the risk. CISA’s catalog entry notes that this bug can be combined with CVE-2026-86060, a RouterOS SSH login flaw that lets an attacker alter the router’s internal policy mask and escalate privileges, so that CVE-2026-86060 can be exploited without credentials. CVE-2026-86060 carries a CVSS 4.0 score of 9.2 and has been in the KEV catalog since 10 September. The newly listed flaw is the piece that removes the need for a valid session, so the combination amounts to unauthenticated takeover of an exposed router. Fixed releases are 6.49.21 and 7.23.4 on the long-term branches and 7.24.2 on the stable branch.

Gaps in the public record

Neither entry names a threat actor, a campaign, or the sectors being targeted, and CISA gives no indication of how widespread the activity is. Ransomware use is recorded as unknown for both, which is not the same as ruled out. No indicators of compromise accompanied the listing. Unlike the SharePoint entry, the RouterOS entry is not flagged for forensic triage, though the chained CVE-2026-86060 path gives little reason to assume an exposed, unpatched router is clean. CISA did flag CVE-2026-86060 itself for forensic triage. Exploitation status in this article is CISA’s finding; Quietlytic has not independently observed it.

Who is exposed

For SharePoint, the exposure is any organisation still running an on-premises farm on the versions above. SharePoint Online is not listed in the NVD configuration data. Because exploitation requires some level of authenticated access, internet-facing farms with broad external sharing or contractor accounts deserve the closest look, as do farms where a phished employee account could reach the server.

For RouterOS, the exposure is any device on a build older than the fixed releases with its SSH service reachable by an untrusted network. Managed service providers and ISPs that operate fleets of MikroTik equipment should treat this as a fleet-wide problem rather than a device-by-device one, since a single unpatched image usually means many unpatched units.

Priorities for defenders

  1. Close SSH on MikroTik devices first. If RouterOS SSH is reachable from the internet, restrict it to management addresses through the router’s IP service settings or firewall rules today. This blunts both RouterOS flaws while upgrades are scheduled.
  2. Upgrade RouterOS to 6.49.21, 7.23.4 or 7.24.2 or later. Confirm the running version on every device afterwards; an upgrade that did not complete leaves the device exactly as exposed as before.
  3. Check routers for tampering. Review configuration exports against a known-good copy and look for unexpected users, scheduler entries, scripts and files. A router that was reachable while vulnerable should be treated as suspect until checked.
  4. Patch SharePoint Server and verify the build. Apply the Microsoft update listed in the vendor advisory for CVE-2026-65660 and confirm the farm reports a build at or above the fixed level on every server in the farm.
  5. Hunt on SharePoint servers before closing the ticket. Following CISA’s forensic triage flag, review web server and SharePoint logs since mid-August for unusual requests from authenticated accounts, look for unfamiliar files in web directories, and check for new or changed site collection administrators. Rotate credentials for any service accounts on a server that shows signs of access.
  6. Tighten SharePoint access paths. Limit external exposure where it is not required and review which external and guest accounts can reach the farm.

Organisations outside the US federal government are not bound by the 28 September deadline, but the KEV catalog remains one of the clearest public signals separating flaws attackers are using from those they might. One of these entries completes an already-exploited router takeover chain, and the other gives a foothold on a document platform that many organisations treat as a trusted internal system. Both belong ahead of the ordinary patch queue.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources

  1. CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog (25 September 2026)
  2. CISA — Known Exploited Vulnerabilities Catalog
  3. NVD — CVE-2026-65660
  4. NVD — CVE-2026-67279
  5. NVD — CVE-2026-86060

Related intelligence


Cross-referenced intelligence


Analyst tools