securityaffairs.com 25 Sept 2026, 21:03 UTC

CISA Warns of Active MikroTik RouterOS Attacks and SharePoint Flaw

CISA Warns of Active MikroTik RouterOS Attacks and SharePoint Flaw
CyberSIXT Evidence Panel

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue: CVE-2026-65660, a Microsoft SharePoint code-injection flaw with a CVSS score of 8.8, and CVE-2026-67279, a MikroTik RouterOS vulnerability scored at 6.9. CVE-2026-65660 affects SharePoint Server 2016, 2019 and Subscription Edition, and allows an authenticated, low-privileged attacker to execute arbitrary code remotely.

CVE-2026-67279 affects the RouterOS SSH protocol. It can allow an unauthenticated attacker to bypass the usual authentication process, open a session channel and execute commands, potentially creating or modifying files on the device. CERT Polska confirmed that the flaw is being actively exploited against internet-exposed RouterOS devices, with successful attacks reported from at least 2 September 2026.

The organisation said the vulnerability can be chained with CVE-2026-86060 to obtain full administrative access without authentication, in a campaign referred to as the MikroTrick chain.

Under Binding Operational Directive 22-01, US federal civilian executive branch agencies must address the vulnerabilities by CISA’s deadline of 28 September 2026. The report also recommends that private organisations review the KEV catalogue and remediate affected SharePoint and RouterOS deployments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline