Skip to content
BreakingCoding

SharePoint, MikroTik bugs hit CISA's exploited list

CISA added a Microsoft SharePoint Server bug and a MikroTik RouterOS exploit chain to its exploited-vulnerability list, with a patch deadline of September 28 for U.S. federal agencies.

By Tech AI Wire Team

3 min read

XLinkedIn
A black home-office router standing upright on a clear stand, its row of Ethernet ports facing the camera, on a light-gray backdrop.

By the numbers

CVSS score for the SharePoint flaw
8.8 / 10
CVSS score for the first MikroTik flaw in the chain
6.9 / 10
date active MikroTik exploitation was first confirmed
Sept. 2

Two more actively exploited flaws landed on a U.S. government watchlist this week. The list is the Cybersecurity and Infrastructure Security Agency's, or CISA's, Known Exploited Vulnerabilities catalog. The new entries are a Microsoft SharePoint Server bug and a chained pair of flaws in MikroTik's RouterOS network operating system. Federal civilian agencies faced a patch deadline of September 28, 2026, for both.

The SharePoint flaw

Security Affairs reports that CVE-2026-65660 affects SharePoint Server 2016, 2019, and Subscription Edition. It scores 8.8 out of 10 on the CVSS severity scale, the standard measure security teams use to rank how dangerous a bug is. The flaw lets an attacker who already has a low-privileged, logged-in account run their own code on the server, a step up from what it does normally allow.

Microsoft first described the bug as a spoofing issue, one that could trick a user into trusting fake content. It later updated its own advisory to say the bug enables remote code execution instead. The Hacker News says Microsoft confirmed "reliable evidence of observed attacks" as of September 25, 2026.

The MikroTik exploit chain

The second entry is not one bug but two, used together. CVE-2026-67279, scoring 6.9 on CVSS, is a flaw in how RouterOS handles the SSH remote-login protocol. On its own, it lets someone connect without a password and open a session channel, then send a limited set of commands.

Chained with a second flaw, CVE-2026-86060, an attacker can go further. That bug lets them supply a fake "policy mask." A policy mask is a setting meant to limit what a logged-in session can do. Combined, the two bugs give an outside attacker full administrative control of the router with no password at all. Security Affairs and The Hacker News agree both flaws affect RouterOS 7.x.

Poland's national computer emergency response team, CERT Polska, confirmed real attacks against exposed RouterOS devices going back to at least September 2, 2026, according to Security Affairs.

What's affected and by when

ItemDetail
CVE-2026-65660SharePoint Server 2016, 2019, Subscription Edition; CVSS 8.8
CVE-2026-67279RouterOS 7.x, SSH auth bypass; CVSS 6.9
CVE-2026-86060RouterOS 7.x, policy-mask spoof; chains with the flaw above
Confirmed exploited sinceSept. 25 (SharePoint), Sept. 2 (RouterOS chain)
Federal deadlineSeptember 28, 2026

Both entries fall under CISA's Binding Operational Directive 22-01. That is the standing 2022 order requiring federal civilian agencies to patch any flaw on the exploited-vulnerabilities list. Agencies must patch by the date CISA sets for each entry.

What this means for developers

If your organization runs SharePoint Server on-premises, check that you are on a build with Microsoft's fix for CVE-2026-65660. Also audit which accounts hold even low-privilege access, since that is all this bug needs to work. SharePoint Online, Microsoft's hosted version, is not affected.

If you manage MikroTik routers, update RouterOS first, especially on any router reachable from the public internet. Then confirm SSH access is not exposed to the open internet at all. A firewall rule that limits SSH to a known management network closes off this entire exploit chain, even before you patch. That works because both flaws in the chain start with an unauthenticated SSH connection.

For both products, check logs for unexpected administrative logins or configuration changes going back to early September. CERT Polska's timeline shows real attacks predate today's public disclosure by more than three weeks.

Sources

  1. SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild - The Hacker News
  2. U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog - Security Affairs

Related articles

A black rack-mount network appliance with the NetScaler wordmark on its front bezel, on a plain gray backdrop.
Coding

Citrix NetScaler flaws: CISA sets a Sept. 30 deadline

CISA added two Citrix NetScaler flaws, both scoring 9.5 of 10 on the CVSS severity scale, to its exploited-vulnerability list on September 27, giving federal agencies until September 30 to patch.

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.