CISA Adds SharePoint RCE and MikroTik Bypass to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026, ordering federal civilian agencies to remediate active vulnerabilities in Microsoft SharePoint Server and MikroTik RouterOS. The SharePoint issue, tracked as CVE-2026-65660, is a high-severity code-injection vulnerability affecting SharePoint Server 2016, 2019, and Subscription Edition that permits authenticated, low-privileged remote attackers to execute arbitrary code. The second entry, CVE-2026-67279, represents an improper enforcement of behavioral workflow in MikroTik RouterOS SSH session handling, enabling unauthenticated attackers to execute commands and manipulate system files.
This development carries immediate operational urgency for infrastructure and enterprise operations teams. On-premises SharePoint deployments often serve as critical data repositories holding internal intellectual property, sensitive documents, and compliance records. Once attackers gain code execution inside SharePoint, lateral movement across domain controllers and hybrid cloud directories is rapid. Simultaneously, unauthenticated execution flaws on edge networking equipment like MikroTik routers provide threat actors with persistent ingress footholds that bypass perimeter controls and leave traditional host-based endpoint detection blind.
This advisory underscores a continued industry pattern: opportunistic and state-aligned threat actors consistently pivot away from heavily monitored cloud endpoints toward unmanaged perimeter appliances and legacy self-hosted enterprise platforms. While modern SaaS platforms absorb patch management behind cloud boundaries, self-hosted and hybrid enterprise stacks remain uniquely exposed to chained exploits where low-privilege access is instantly escalated to full system takeover.
In practice, security operations and DevOps teams should immediately audit their external attack surface for exposed SharePoint endpoints and MikroTik interfaces. Federal agencies face strict Binding Operational Directive deadlines, but private sector organizations should mirror this urgency by isolating internet-facing management ports, restricting administrative SSH access to dedicated VPN/bastion segments, and applying the latest vendor-supplied patches. Beyond patching, practitioners must conduct forensic triage on affected systems—inspecting process execution histories, abnormal account creations, and SSH session anomalies—to verify that threat actors did not establish persistence prior to mitigation.
Read original source