The U.S. Cybersecurity and Infrastructure Security Agency has added vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. The catalog records confirmed exploitation and directs U.S. federal civilian agencies to apply vendor mitigations by September 28, 2026.
The entries affect different layers of infrastructure
CVE-2026-65660 is a SharePoint code-injection vulnerability that Microsoft describes as allowing an authorized attacker to execute code over a network. CVE-2026-67279 affects RouterOS workflow enforcement and can allow an unauthenticated client to open a session channel and send an execution request. CISA notes that the RouterOS weakness can be chained with CVE-2026-86060 for unauthenticated exploitation.
The two entries should not be treated as a single technical flaw. One concerns collaboration-server code execution, while the other is part of a router attack chain. Their shared significance is operational: both are now associated with observed exploitation rather than theoretical risk alone.
Inventory and exposure determine priority
Defenders should identify affected SharePoint and RouterOS assets, confirm internet exposure, apply vendor guidance and preserve evidence where compromise is suspected. Unsupported or unmitigated systems may require isolation or retirement. Monitoring should continue after patching because remediation does not remove persistence established before the update. SectechMedia follows related operational risks in its cyber-physical security channel.

Leave a Reply