Back to News

CISA Adds Exploited SharePoint RCE and MikroTik Flaws Enabling RouterOS Device Takeovers

CISA Adds Exploited SharePoint RCE and MikroTik Flaws Enabling RouterOS Device Takeovers

SharePoint RCE vulnerability CVE-2026-65660 and MikroTik RouterOS vulnerability CVE-2026-67279 have been added to the U.S. CISA Known Exploited Vulnerabilities catalog after active exploitation was reported. Attackers are also chaining CVE-2026-67279 with the previously listed CVE-2026-86060 in an exploit chain called “MikroTrick,” which provides full unauthenticated administrative access to vulnerable RouterOS 7.x devices.

Key Points

  • CVE-2026-65660 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
  • Microsoft updated its advisory after initially describing the SharePoint issue as spoofing and now identifies remote code execution as the impact.
  • MikroTrick combines CVE-2026-67279 and CVE-2026-86060 to take over internet-exposed RouterOS 7.x devices without a password.
  • Microsoft reported reliable evidence of attacks against the SharePoint vulnerability as of September 25, 2026.
  • Organizations should apply vendor updates, restrict remote administration, and monitor for suspicious SharePoint and RouterOS activity.

SharePoint vulnerability updated to RCE

CVE-2026-65660 was initially described by Microsoft as a spoofing vulnerability. Microsoft later updated its advisory to state that the flaw can be abused for remote code execution through code injection.

The vulnerability requires an authorized attacker (authenticated) and can be exploited over a network. The cited CVSS score is 8.8, rated High. Affected products include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Specific affected builds were not identified in the reporting.

“As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.” – Microsoft

Microsoft has not disclosed who was responsible for the attacks, when exploitation began, how many organizations were targeted, how many compromises succeeded, or what attackers did after gaining access.

MikroTik flaws form MikroTrick chain

CVE-2026-67279 is an improper enforcement of behavioral workflow vulnerability with a cited CVSS score of 6.9, rated Medium. It allows an unauthenticated client to create a session channel and send an exec request.

CVE-2026-86060 is an argument injection flaw in the RouterOS login process. Attacker-controlled data can cause the login process to treat the data as a trusted administrative identity through policy mask manipulation. CISA added CVE-2026-86060 to the KEV catalog on September 11, 2026.

CERT Polska and Bishop Fox reported that chaining the two flaws produces full unauthenticated administrative access to internet-exposed RouterOS devices. Bishop Fox reproduced the complete takeover on vulnerable RouterOS 7.x builds.

“Combining the two vulnerabilities resulted in full unauthenticated access to the administrative console.” – CERT Polska

Emilio Gallegos of Bishop Fox described the chain as failures at separate trust boundaries.

“MikroTrick combines two failures at different trust boundaries… The first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login. The second causes the login process to treat data from that connection as a trusted administrative identity.” – Emilio Gallegos

“MikroTrick exposes a design risk in privileged software: a feature intended only for trusted local callers becomes a remote attack surface when an upstream component loses track of authentication state.” – Emilio Gallegos

Response and mitigation

CISA’s inclusion of the vulnerabilities in the KEV catalog identifies them as exploited vulnerabilities and creates remediation obligations for federal civilian executive branch agencies. Reporting set September 28, 2026, as the remediation deadline for CVE-2026-86060 under those obligations.

Administrators should apply Microsoft’s SharePoint security updates and update MikroTik RouterOS to a fixed stable release. MikroTik administrators should disable remote WinBox and WebFig administration from the internet and restrict administrative access to trusted IP addresses.

Detection measures include looking for unexpected session channels created by unauthenticated IP addresses on MikroTik devices, auditing RouterOS login activity for attacker-controlled policy masks, and monitoring SharePoint logs for unauthorized code execution attempts or unusual service behavior. Network segmentation, tighter access controls, and immediate patching are also recommended while active exploitation remains reported.

Sources

Mayank Mehra

Written by

Mayank Mehra

Mayank Mehra is a cybersecurity professional with 8+ years of hands-on experience in application security, penetration testing, and AI Security. He holds industry-recognised certifications including CEH, CAPEN, and CRTP, and has worked across vulnerability assessments, penetration testing and securing AI-powered systems.

View all posts →