CVE -2026-65660 in Microsoft SharePoint and a new vulnerability in MikroTik RouterOS have been added to the CISA KEV list as there are indications of active exploitation. Administrators are urged to immediately review their installations and apply available fixes.
The warning concerns two different products, but they share the common denominator of exposing critical infrastructure to attacks that are already underway. The Hacker News reports that CISA added the relevant entries to the Known Exploited Vulnerabilities list, asking US federal agencies to complete the necessary actions by September 28.
The Active Exploit is not a simple risk assessment. It describes vulnerabilities that have been shown to be used in real attacks, so immediate remediation should be a priority, not just monitoring related announcements.
In this case, active exploitation concerns both the collaboration service and the network equipment, with different technical requirements for each product.
See also: SharePoint vulnerability allows authenticated remote execution

CVE-2026-65660 in SharePoint
CVE -2026-65660 concerns a vulnerability in the way Microsoft Office SharePoint handles code generation. The original posting described it as a spoofing issue, but Microsoft updated its advisory, acknowledging that an authorized attacker could execute code over a network.
NVD records CVE -2026-65660 as a code injection and attributes the related entry to Microsoft. The available CVSS 3.1 score listed in the updated reports is 8.8, while Microsoft stated that on September 25th it had credible evidence of observed exploitation attempts.
This does not mean that every SharePoint server has been compromised or that the number of victims is known. It does mean, however, that CVE-2026-65660 should not be treated as a hypothetical. The Microsoft Security Response Center is the place to go to confirm the available patch and affected versions.
Organizations using hybrid deployments need to separately scan servers that remain on-premises for CVE-2026-65660. Having perimeter protection services does not negate the risk, as an attack can be initiated from an account with limited privileges. Re-examining privileges and disabling old accounts reduces the potential for abuse.

The MikroTrick chain on routers
The second entry concerns CVE-2026-67279 in MikroTik RouterOS. The vulnerability could allow an unauthenticated client to open a session channel and send an execution request. CISA has included it in the KEV list due to evidence of active exploitation, with a CVSS score of 6.9.
CVE-2026-67279 is linked to CVE-2026-86060 in a chain that researchers have dubbed MikroTrick. As CERT Polska, the combination of the two vulnerabilities can lead to full administrative control of a RouterOS that exposes management services to the internet, without requiring a password.
The attack is not limited to initial access. After gaining administrator privileges, an attacker could modify the router's configuration, monitor or redirect traffic, and use the device as an entry point into the internal network. A single number of affected devices has not been disclosed.
MikroTik notes that most default configurations do not directly expose this service. However, this does not cover devices that have been manually allowed SSH access from the internet. Network administrators should check firewall rules, whitelists, and recent configuration changes.
See also: ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What should administrators do?
Teams managing SharePoint should verify that the latest Microsoft update is installed and review logs for unusual connections or actions. Having an authenticated prerequisite is not a reason to postpone, especially in environments with multiple accounts and external access.
For RouterOS, MikroTik recommends upgrading to versions 7.25 beta 3, 7.24.2, 7.23.4 or 6.49.21, depending on the support channel. In addition, SSH should not be open on untrusted networks. If remote management is necessary, access via a strong VPN, such as WireGuard, is preferred.

After the upgrade, RouterOS administrators should check the logs for “Flagged” and look for unknown users, scripts, or configuration changes. The SecNews technical team also recommends recording recovery actions so that any suspicious devices can be isolated and investigated without losing critical data.
See also: Patch Tuesday September 2026: Microsoft fixes over 960 vulnerabilities
The simultaneous presence of CVE-2026-65660 in active exploitation and a chain targeting RouterOS demonstrates why KEV lists should become an immediate operational security priority. Installing patches, mitigating exposure, and monitoring for signs of compromise are key steps to mitigate risk.
