CISA added CVE-2026-65660, a code-injection vulnerability in Microsoft SharePoint Server 2016, 2019, and Subscription Edition, to its Known Exploited Vulnerabilities catalog. The flaw allows an authenticated, low-privileged network user to execute arbitrary code remotely; CISA flags it for forensic triage following remediation.
CISA also listed CVE-2026-67279 in MikroTik RouterOS, which allows an unauthenticated client to open a session channel and issue an exec request. Active exploitation has been reported against internet-exposed devices, and attackers can chain it with CVE-2026-86060 to gain unauthenticated full administrative access. U.S. federal civilian agencies must remediate both vulnerabilities by September 28, 2026 under BOD 26-04 guidance.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CISA updated its Known Exploited Vulnerabilities catalog, adding Microsoft SharePoint code-injection flaw CVE-2026-65660 and MikroTik RouterOS authentication-workflow flaw CVE-2026-67279, increasing the catalog from 1,723 to 1,725 entries. The SharePoint flaw permits remote code execution by an authorized low-privileged user, while the RouterOS flaw can permit unauthenticated command execution and may be chained with CVE-2026-86060.
Successful attacks against internet-exposed MikroTik RouterOS devices using the MikroTrick exploit chain date to at least September 2, 2026. CERT Polska reported that chaining CVE-2026-67279 with CVE-2026-86060 could yield unauthenticated full administrative access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.