SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- ID
- 28874
- Status
- summarized
- Published
- 26 Sep 2026, 4:49 PM
- Fetched
- 26 Sep 2026, 7:09 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 26 Sep 2026, 7:10 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
CISA added CVE-2026-65660 (CVSS 8.8, code injection in Microsoft SharePoint Server, allowing network code execution) and CVE-2026-67279 (CVSS 6.9, MikroTik RouterOS workflow enforcement flaw) to its Known Exploited Vulnerabilities catalog, with Microsoft stating that as of 9/25/2026 it had reliable evidence of attacks exploiting the SharePoint flaw — which it originally described as spoofing before reclassifying it as RCE. MikroTrick chains CVE-2026-67279 with CVE-2026-86060, an argument injection flaw in the RouterOS login process, to give an unauthenticated attacker full admin console access; CERT Polska documented the chain and Bishop Fox said it reproduced complete administrative takeover on vulnerable RouterOS 7.x builds.
Why it matters
Two decisions for this week: check whether any on-prem SharePoint Server you run has the CVE-2026-65660 patch, since Microsoft now confirms in-the-wild exploitation and has not disclosed who was targeted or what attackers did after entry. Then check whether any MikroTik RouterOS 7.x device in your office, lab, or client network has its admin interface reachable from the internet — the MikroTrick chain needs no password and yields full admin control, so if you cannot patch immediately, restricting management access to an internal network is the fallback.
Discussion angle
Microsoft first labelled the SharePoint flaw a spoofing bug and only later confirmed RCE after CISA KEV-listed it — what does that say about triaging by vendor severity labels versus waiting for exploitation evidence, and who on your team owns that call?