www.cyber.gc.ca Active Exploitation of SharePoint and MikroTik Vulnerabilities Confirmed
Article Content
- •CVE-2026-65660 allows authenticated code execution on SharePoint servers.
- •CISA confirmed active exploitation of both SharePoint and MikroTik vulnerabilities.
- •Federal agencies must apply fixes by September 28, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The vulnerabilities include CVE-2026-65660, a code injection flaw in Microsoft SharePoint Server, which allows authenticated attackers to execute arbitrary code, and CVE-2026-67279, a flaw in MikroTik RouterOS that enables unauthenticated access to administrative controls. Microsoft reported reliable evidence of exploitation of CVE-2026-65660 as of September 25, 2026. The SharePoint vulnerability has a CVSS score of 8.8, indicating high severity, while the MikroTik flaw has a CVSS score of 6.9. Organizations using affected systems are urged to apply security updates and review authentication records for unusual activity. The vulnerabilities pose significant risks, especially for systems exposed to the internet. CISA has mandated that federal agencies apply fixes by September 28, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-65660 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…