Skip to content
Active Exploitation of SharePoint and MikroTik Vulnerabilities Confirmed

Active Exploitation of SharePoint and MikroTik Vulnerabilities Confirmed

First seen 26 Sep 2026, 17:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:54 UTC
  • •CVE-2026-65660 allows authenticated code execution on SharePoint servers.
  • •CISA confirmed active exploitation of both SharePoint and MikroTik vulnerabilities.
  • •Federal agencies must apply fixes by September 28, 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The vulnerabilities include CVE-2026-65660, a code injection flaw in Microsoft SharePoint Server, which allows authenticated attackers to execute arbitrary code, and CVE-2026-67279, a flaw in MikroTik RouterOS that enables unauthenticated access to administrative controls. Microsoft reported reliable evidence of exploitation of CVE-2026-65660 as of September 25, 2026. The SharePoint vulnerability has a CVSS score of 8.8, indicating high severity, while the MikroTik flaw has a CVSS score of 6.9. Organizations using affected systems are urged to apply security updates and review authentication records for unusual activity. The vulnerabilities pose significant risks, especially for systems exposed to the internet. CISA has mandated that federal agencies apply fixes by September 28, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-65660 published
Microsoft disclosed a code injection vulnerability in SharePoint Server affecting multiple versions.
cyber.gc.ca
2026-09-05
CVE-2026-86060 published
MikroTik RouterOS flaw published, allowing unauthenticated access.
Thehackernews
2026-09-10
CVE-2026-86060 added to CISA KEV
CISA listed the MikroTik RouterOS vulnerability as actively exploited.
Thehackernews
2026-09-25
CVE-2026-65660 added to CISA KEV
CISA confirmed active exploitation of the SharePoint vulnerability.
News.Lavx.Hu
2026-09-26
CVE-2026-67279 first public PoC
Proof-of-concept code for the MikroTik RouterOS vulnerability was released.
Thehackernews

More articles in this cluster (6)

Following this threat?

Track CVE-2026-65660 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed