Microsoft SharePoint, MikroTik RouterOS Flaws Actively Exploited: CISA
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The first vulnerability is CVE-2026-65660, a code injection flaw in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network. Microsoft initially described the issue as a spoofing vulnerability but has since updated its advisory to note it can be used for remote code execution.
CISA added this vulnerability to its KEV catalog on September 25, 2026, and notes that 'as of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.'
The second vulnerability is CVE-2026-67279, an improper enforcement of behavioral workflow flaw in Mikrotik RouterOS. This issue can be chained with CVE-2026-86060 to allow an unauthenticated client to open a session channel and send an exec request.