CISA Flags SharePoint and MikroTik RouterOS Flaws as Actively Exploited
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two more vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026, citing confirmed real-world exploitation: a code-injection flaw in Microsoft Office SharePoint and an authentication-related flaw in MikroTik RouterOS. Notably, the SharePoint issue was initially classified by Microsoft as a lower-severity "spoofing" vulnerability, but the company has since updated its own advisory to state it can in fact be abused for remote code execution, after confirming reliable evidence of attacks exploiting it. The RouterOS flaw, meanwhile, is one half of a two-vulnerability exploit chain researchers have named "MikroTrick," which Polish and international security researchers have shown grants complete, unauthenticated administrative control of vulnerable routers.
Who is affected
Organizations running on-premises Microsoft SharePoint Server deployments affected by CVE-2026-65660 are at risk of remote code execution by an authorized attacker (i.e., one with some level of existing access) over the network. Separately, any internet-exposed MikroTik RouterOS device is potentially affected by the MikroTrick chain, which combines CVE-2026-67279 with a previously disclosed argument-injection flaw, CVE-2026-86060, in the RouterOS login process. Because MikroTik routers are widely deployed by ISPs, small businesses, and home users alike, and the MikroTrick chain requires no valid credentials, exposure is broad wherever RouterOS management or login interfaces are reachable from untrusted networks.
Why it matters
The SharePoint case is a useful reminder that initial vendor severity classifications can change as exploitation evidence emerges — a flaw first described as "spoofing" was later confirmed capable of remote code execution once Microsoft observed real attacks, meaning organizations that deprioritized it based on the original classification may need to revisit that decision. The MikroTrick chain is arguably the more urgent of the two: according to the researchers who reproduced it, one flaw lets an unauthenticated client reach functionality that should only be available after login, and the second causes the login process itself to trust attacker-controlled data as if it came from an authenticated administrative session. The combination collapses two separate trust boundaries into one exploitable path, illustrating a broader design lesson — that internal-assumption features (built for trusted local callers) become dangerous once an upstream authentication check can be tricked into treating untrusted input as trusted.
Technical details
- CVE-2026-65660 — CVSS 8.8. Code injection vulnerability in Microsoft Office SharePoint; originally described as a spoofing issue, later confirmed by Microsoft to allow remote code execution by an authorized attacker over a network. Microsoft states it has reliable evidence of observed attacks as of September 25, 2026.
- CVE-2026-67279 — CVSS 6.9. Improper enforcement of behavioral workflow in MikroTik RouterOS, allowing an unauthenticated client to open a session channel and send an exec request — one half of the "MikroTrick" chain.
- CVE-2026-86060 — CVSS 9.2 (added to KEV separately on September 11, 2026). Argument-injection flaw in the RouterOS login process that allows an attacker to supply a controlled policy mask, completing the MikroTrick chain for full administrative takeover on vulnerable RouterOS 7.x builds.
- Federal deadlines: FCEB agencies have until September 28, 2026 to remediate the RouterOS-related flaws per CISA's KEV requirements.
- Independent verification: CERT Polska and Bishop Fox have both independently reproduced full administrative takeover using the MikroTrick chain.
Recommended actions
- Apply the latest Microsoft security updates for SharePoint Server addressing CVE-2026-65660 without delay, and treat it as remote-code-execution-capable rather than relying on its original "spoofing" classification.
- Update MikroTik RouterOS to a version that addresses both CVE-2026-67279 and CVE-2026-86060; patching only one of the two flaws in the MikroTrick chain is insufficient, since either alone does not grant full takeover.
- Ensure RouterOS management, login, and API interfaces are not reachable from the public internet — restrict access to trusted management networks or VPN-only access.
- Review router configuration and administrative account lists for signs of unauthorized changes if any RouterOS device has been internet-exposed and unpatched during this period.
- Cross-reference your SharePoint and RouterOS inventory against CISA's KEV catalog and prioritize remediation using the published federal deadlines as an urgency benchmark, even for non-federal organizations.
- Monitor vendor advisories for both products, since Microsoft's revision of the SharePoint flaw's severity after the fact shows initial classifications can understate real-world risk.
Sources
- https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
