U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
CISA added exploited Microsoft SharePoint and MikroTik RouterOS flaws to KEV, due September 28.
CISA added CVE-2026-65660 and CVE-2026-67279 to the Known Exploited Vulnerabilities catalog, ordering federal agencies to fix them by September 28, 2026, under BOD 22-01. CVE-2026-65660 (CVSS 8.8) is a Microsoft SharePoint Server code-injection flaw in 2016, 2019, and Subscription Edition that lets an authenticated low-privileged attacker execute arbitrary code. CVE-2026-67279 (CVSS 6.9) is a MikroTik RouterOS SSH flaw that lets an unauthenticated attacker bypass authentication, open a session, and run commands. CERT Polska says exploitation dates to at least September 2, 2026, and chaining it with CVE-2026-86060 can give full administrative access.
- CISA KEV now includes SharePoint CVE-2026-65660 and RouterOS CVE-2026-67279.
- Federal agencies must remediate both flaws by September 28, 2026.
- SharePoint bug allows low-privileged authenticated remote code execution on 2016, 2019, and Subscription Edition.
- MikroTik flaw is an unauthenticated SSH authentication bypass exploited since at least September 2.
- Chaining it with CVE-2026-86060 can yield full administrative access.
Vulnerabilities mentionedAll →
- CVE-2026-656608.82%Authenticated Code Injection RCE in Microsoft SharePoint Serverpublished · Microsoft SharePoint Server KEV PoC ×2
Full article280 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 25, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-65660 (CVSS score of 8.8) Microsoft SharePoint Code Injection Vulnerability
- CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary code remotely. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
The second flaw added to the catalog, tracked as CVE-2026-67279 (CVSS score of 6.9), is an SSH protocol flaw in MikroTik RouterOS that allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel and execute commands, potentially creating or modifying files on the device. CERT Polska confirmed that the flaw is being actively exploited in the wild and that, when chained with CVE-2026-86060, it can lead to full administrative access without authentication.
CERT Polska reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaws by September 28, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)