SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
AI-summarised brief · reviewed before publication
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE‑2026‑65660, a Microsoft SharePoint Server flaw that now enables remote code execution, and CVE‑2026‑67279, a MikroTik RouterOS flaw chained with CVE‑2026‑86060 in the MikroTrick exploit. The chain grants unauthenticated attackers full administrative control of exposed routers. Microsoft has not disclosed attacker identities or impact scope, while CERT Polska confirmed the exploit’s effectiveness. Federal agencies must patch by September 28, 2026.
💡 Why It Matters
- · The simultaneous exploitation of SharePoint and RouterOS demonstrates attackers’ growing ability to combine separate weaknesses into a single, high‑impact attack vector, forcing organizations to prioritize patching and reassess trust boundaries in critical infrastructure.