SharePoint, MikroTik bugs hit CISA's exploited list
CISA added a Microsoft SharePoint Server bug and a MikroTik RouterOS exploit chain to its exploited-vulnerability list, with a patch deadline of September 28 for U.S. federal agencies.
3 min read

By the numbers
- CVSS score for the SharePoint flaw
- 8.8 / 10
- CVSS score for the first MikroTik flaw in the chain
- 6.9 / 10
- date active MikroTik exploitation was first confirmed
- Sept. 2
Two more actively exploited flaws landed on a U.S. government watchlist this week. The list is the Cybersecurity and Infrastructure Security Agency's, or CISA's, Known Exploited Vulnerabilities catalog. The new entries are a Microsoft SharePoint Server bug and a chained pair of flaws in MikroTik's RouterOS network operating system. Federal civilian agencies faced a patch deadline of September 28, 2026, for both.
The SharePoint flaw
Security Affairs reports that CVE-2026-65660 affects SharePoint Server 2016, 2019, and Subscription Edition. It scores 8.8 out of 10 on the CVSS severity scale, the standard measure security teams use to rank how dangerous a bug is. The flaw lets an attacker who already has a low-privileged, logged-in account run their own code on the server, a step up from what it does normally allow.
Microsoft first described the bug as a spoofing issue, one that could trick a user into trusting fake content. It later updated its own advisory to say the bug enables remote code execution instead. The Hacker News says Microsoft confirmed "reliable evidence of observed attacks" as of September 25, 2026.
The MikroTik exploit chain
The second entry is not one bug but two, used together. CVE-2026-67279, scoring 6.9 on CVSS, is a flaw in how RouterOS handles the SSH remote-login protocol. On its own, it lets someone connect without a password and open a session channel, then send a limited set of commands.
Chained with a second flaw, CVE-2026-86060, an attacker can go further. That bug lets them supply a fake "policy mask." A policy mask is a setting meant to limit what a logged-in session can do. Combined, the two bugs give an outside attacker full administrative control of the router with no password at all. Security Affairs and The Hacker News agree both flaws affect RouterOS 7.x.
Poland's national computer emergency response team, CERT Polska, confirmed real attacks against exposed RouterOS devices going back to at least September 2, 2026, according to Security Affairs.
What's affected and by when
| Item | Detail |
|---|---|
| CVE-2026-65660 | SharePoint Server 2016, 2019, Subscription Edition; CVSS 8.8 |
| CVE-2026-67279 | RouterOS 7.x, SSH auth bypass; CVSS 6.9 |
| CVE-2026-86060 | RouterOS 7.x, policy-mask spoof; chains with the flaw above |
| Confirmed exploited since | Sept. 25 (SharePoint), Sept. 2 (RouterOS chain) |
| Federal deadline | September 28, 2026 |
Both entries fall under CISA's Binding Operational Directive 22-01. That is the standing 2022 order requiring federal civilian agencies to patch any flaw on the exploited-vulnerabilities list. Agencies must patch by the date CISA sets for each entry.
What this means for developers
If your organization runs SharePoint Server on-premises, check that you are on a build with Microsoft's fix for CVE-2026-65660. Also audit which accounts hold even low-privilege access, since that is all this bug needs to work. SharePoint Online, Microsoft's hosted version, is not affected.
If you manage MikroTik routers, update RouterOS first, especially on any router reachable from the public internet. Then confirm SSH access is not exposed to the open internet at all. A firewall rule that limits SSH to a known management network closes off this entire exploit chain, even before you patch. That works because both flaws in the chain start with an unauthenticated SSH connection.
For both products, check logs for unexpected administrative logins or configuration changes going back to early September. CERT Polska's timeline shows real attacks predate today's public disclosure by more than three weeks.
Sources
Related articles

PeopleSoft CVE-2026-35273: one encoded letter beats WAFs
ShinyHunters is mass-exploiting Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) again, dodging WAF rules by writing one letter of the path as %50.

Citrix NetScaler flaws: CISA sets a Sept. 30 deadline
CISA added two Citrix NetScaler flaws, both scoring 9.5 of 10 on the CVSS severity scale, to its exploited-vulnerability list on September 27, giving federal agencies until September 30 to patch.

Rust is now a tier-1 language at Microsoft
Microsoft made Rust a tier-1 language beside C++, C# and TypeScript. More than 100 of its repositories now build Rust code.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.