Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

CISA Adds Critical Microsoft SharePoint and MikroTik RouterOS Vulnerabilities to Known Exploited Vulnerabilities Catalog

Cahyo Dewo, September 27, 2026

The United States Cybersecurity and Infrastructure Security Agency (CISA) has officially expanded its Known Exploited Vulnerabilities (KEV) catalog, adding two high-severity security flaws that are currently being leveraged by threat actors in the wild. The inclusion of these vulnerabilities—impacting Microsoft SharePoint Server and MikroTik’s RouterOS—underscores a growing trend in which attackers target foundational infrastructure to achieve remote code execution and administrative takeover. As of September 25, 2026, federal agencies are under a strict mandate to patch these systems to mitigate the risk of unauthorized access and potential data exfiltration.

The Escalating Threat to SharePoint Server

The most concerning addition to the KEV catalog is CVE-2026-65660, a vulnerability initially mischaracterized as a minor spoofing issue. Microsoft, through its Security Response Center (MSRC), has since updated its advisory to reflect the true severity of the flaw, acknowledging that it facilitates remote code execution (RCE).

The transition from a "spoofing" classification to an "RCE" designation is significant in the cybersecurity landscape. An RCE vulnerability allows an attacker to execute arbitrary commands on a target server, effectively granting them the same privileges as the user running the service—often an administrative or system account. By chaining this flaw with other weaknesses, attackers can gain a foothold within enterprise networks, pivot laterally, and establish persistence.

While Microsoft has confirmed the existence of "reliable evidence of observed attacks," the company has maintained a degree of opacity regarding the specifics of these campaigns. Security analysts suggest that the lack of public disclosure regarding the identities of the threat actors or the scale of the compromise is common when investigations are ongoing. However, the move by CISA to elevate this to the KEV catalog serves as a clear warning to organizations running on-premises SharePoint environments: the window for passive patching has closed.

The MikroTrick Exploit Chain: A Design Flaw in Authentication

The second major development involves the MikroTik RouterOS, which has been targeted by an exploit chain dubbed "MikroTrick." This chain consists of two distinct vulnerabilities: CVE-2026-67279 and CVE-2026-86060.

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The mechanism behind MikroTrick is a sophisticated example of how modern exploits bypass traditional security boundaries. According to technical analysis provided by CERT Polska and confirmed by security researchers at Bishop Fox, the exploit chain effectively circumvents the authentication process entirely. CVE-2026-67279 enables an unauthenticated attacker to create a session channel, while CVE-2026-86060 facilitates an argument injection that tricks the system into accepting a malicious policy mask.

The result is full administrative control over internet-exposed routers. Because these devices sit at the perimeter of corporate and home networks, the implications of a compromise are catastrophic. Once an attacker gains administrative access, they can redirect traffic, intercept sensitive data, or enlist the devices into a massive botnet for distributed denial-of-service (DDoS) attacks. Emilio Gallegos of Bishop Fox noted that the vulnerability highlights a fundamental design risk: software features intended for trusted local administration often lack the necessary guardrails when exposed to remote inputs, especially when the device loses track of the authentication state during the login lifecycle.

Chronology of Events and Regulatory Deadlines

The discovery and subsequent tracking of these flaws have occurred over several months, reflecting a coordinated effort between private security researchers, vendors, and government oversight bodies.

  • August 2026: Microsoft issues security updates for SharePoint, initially categorizing CVE-2026-65660 as a spoofing vulnerability.
  • Early September 2026: Independent security researchers identify the potential for RCE and begin observing active exploitation in the field.
  • September 11, 2026: CISA adds CVE-2026-86060 (the argument injection flaw in MikroTik) to the KEV catalog, marking it as a priority for remediation.
  • September 25, 2026: Microsoft updates the advisory for CVE-2026-65660 to reflect the RCE risk; CISA adds both this flaw and the remaining MikroTik vulnerability to the KEV list.
  • September 28, 2026: The official deadline for Federal Civilian Executive Branch (FCEB) agencies to patch these vulnerabilities, as mandated by the Binding Operational Directive (BOD) 22-01.

Analysis of Implications for Enterprise Security

The inclusion of these specific vulnerabilities in the KEV catalog highlights a broader issue in modern network security: the "perimeter-less" enterprise. As organizations rely increasingly on remote management tools and cloud-integrated server environments, the number of entry points for attackers has increased exponentially.

The MikroTrick exploit, in particular, demonstrates the efficacy of "chaining" vulnerabilities. By combining two lower-severity or functional-level bugs, attackers can achieve a high-impact outcome that neither vulnerability could produce on its own. This modular approach to exploitation makes it significantly harder for traditional signature-based intrusion detection systems (IDS) to catch the attack, as each individual step may appear to be a standard administrative request or a malformed packet.

Furthermore, the SharePoint vulnerability serves as a reminder that vendors may sometimes under-report the severity of a flaw during the initial disclosure process. Security teams must treat all "spoofing" or "elevation of privilege" alerts with the same urgency as RCE warnings, particularly when the affected software is a high-value target like a document management or collaboration server.

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Official Responses and Mitigation Strategies

CISA’s mandate is clear: federal agencies must prioritize the patching of these systems immediately. While the directive specifically applies to the FCEB, CISA strongly urges all private sector organizations and critical infrastructure operators to follow suit.

For Microsoft SharePoint users, the recommendation is to audit server logs for any unusual administrative activity and ensure that the latest security patches are applied across all nodes in a farm. Given that SharePoint is often a repository for sensitive corporate data, the impact of a breach is not limited to network control; it extends to the potential theft of intellectual property and regulatory non-compliance.

For MikroTik administrators, the remediation path involves updating RouterOS to the latest build, which includes the necessary patches to close the argument injection and session creation loopholes. Additionally, administrators should follow best practices for router security, which include:

  1. Disabling non-essential services: Administrative interfaces should never be exposed to the public internet. Use VPNs or secure management VLANs to restrict access to local or trusted IPs only.
  2. Strict Firewall Rules: Implement "deny-all" policies by default and only allow traffic on necessary ports.
  3. Credential Rotation: In the event of a suspected breach, all administrative passwords should be rotated, and session tokens should be invalidated.

Conclusion: A Call to Vigilance

The rapid addition of these vulnerabilities to the KEV catalog is a stark reminder that the digital threat landscape remains highly dynamic. Attackers are becoming increasingly proficient at identifying weaknesses in the seams between different software components. As the September 28 deadline approaches, the focus for IT departments must be on rapid, verified remediation.

While the vendors involved—Microsoft and MikroTik—have provided the necessary patches, the responsibility for securing the ecosystem rests with the end-users. In an era where a single unpatched router or server can compromise an entire corporate infrastructure, consistent patch management and a "zero-trust" approach to administrative access are the only effective defenses against evolving exploit chains like MikroTrick. The coming weeks will likely see an increase in attempts to scan for these vulnerabilities, making proactive patching not just a best practice, but a necessity for operational continuity.

Cybersecurity & Digital Privacy addscatalogcisacriticalCybercrimeexploitedHackingknownmicrosoftmikrotikPrivacyrouterosSecuritysharepointvulnerabilities

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes