Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Global Cybersecurity Alert: Exploitation of SharePoint RCE and MikroTik RouterOS Flaws




Global Cybersecurity Alert: Exploitation of SharePoint RCE and MikroTik RouterOS Flaws

A new series of vulnerabilities has been identified, impacting Microsoft SharePoint and Mikrotik RouterOS, with evidence of active exploitation. The vulnerabilities, designated as CVE-2026-65660 and CVE-2026-67279, have been added to the Known Exploited Vulnerabilities (KEV) catalog, highlighting the need for organizations to take immediate action to protect themselves from these exploits. This article provides a detailed analysis of the vulnerabilities, their implications, and the necessary steps to address these weaknesses.

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified two significant security flaws: CVE-2026-65660 and CVE-2026-67279.
  • CVE-2026-65660 is a code injection vulnerability in Microsoft Office SharePoint, allowing authorized attackers to execute code over a network.
  • CVE-2026-67279 is an improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS, allowing unauthenticated access to administrative consoles.
  • The vulnerabilities can be exploited to take full administrative control of internet-exposed routers without a password or SSH key.
  • The implications are profound, with potential for widespread exploitation, and organizations must take immediate action to protect themselves.



  • The cyber landscape has recently been confronted with a stark warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which has identified two significant security flaws impacting Microsoft SharePoint and Mikrotik RouterOS. The two vulnerabilities, designated as CVE-2026-65660 and CVE-2026-67279, have been added to the Known Exploited Vulnerabilities (KEV) catalog, with evidence of active exploitation reported by the agency.

    CVE-2026-65660, a code injection vulnerability in Microsoft Office SharePoint, has been described by Microsoft as a spoofing vulnerability impacting SharePoint Server. This vulnerability allows an authorized attacker to execute code over a network, thereby posing a substantial threat to the security of the affected systems. The agency has noted that Microsoft has reliable evidence of observed attacks against the exploitation of this vulnerability, although the details of the attacks remain unknown, including the identity of those responsible, the time frame over which the attacks have been conducted, the number of organizations targeted, the number of successful attacks, and the actions taken by the attackers once inside the vulnerable service.

    In contrast, CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS, has been chained with CVE-2026-86060, an argument injection flaw in the RouterOS login process, as part of an exploit codenamed MikroTrick. This exploit chain has been employed to take full administrative control of internet-exposed susceptible routers without the need for a password or SSH key. According to the Polish cybersecurity agency, CERT Polska, combining the two vulnerabilities resulted in full unauthenticated access to the administrative console, while CVE-2026-67279 allowed an unauthenticated client to create a session channel, and CVE-2026-86060 allowed it to supply login with an attacker-controlled policy mask.

    The implications of these vulnerabilities are profound, with security researchers and experts alike highlighting the potential for widespread exploitation. Bishop Fox, a security researcher, stated that the complete administrative takeover on vulnerable RouterOS 7.x builds could be achieved through the MikroTrick exploit, which exposes a design risk in privileged software: a feature intended only for trusted local callers becomes a remote attack surface when an upstream component loses track of authentication state. Emilio Gallegos, a security researcher, noted that the vulnerability chain demonstrates a failure in the security architecture of RouterOS, as an unauthenticated connection could be used to reach functionality that RouterOS should expose only after login.

    The impact of these vulnerabilities extends beyond the affected systems, with broader implications for the security posture of organizations and individuals. The addition of these vulnerabilities to the KEV catalog serves as a stark reminder of the ongoing threat landscape and the need for proactive measures to address these weaknesses. As Federal Civilian Executive Branch (FCEB) agencies have until September 28, 2026, to apply the necessary fixes, it is essential for organizations to take immediate action to protect themselves from these exploits.

    The recent exploitation of these vulnerabilities highlights the need for continued vigilance and proactive measures to address security weaknesses. The rapid pace of technological advancement and the evolving threat landscape underscore the importance of ongoing monitoring and assessment to ensure the security of systems and data. As the cybersecurity landscape continues to evolve, it is essential for organizations and individuals to remain vigilant and take proactive steps to protect themselves against emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Global-Cybersecurity-Alert-Exploitation-of-SharePoint-RCE-and-MikroTik-RouterOS-Flaws-ehn.shtml

  • https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-65660

  • https://www.cvedetails.com/cve/CVE-2026-65660/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-67279

  • https://www.cvedetails.com/cve/CVE-2026-67279/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-86060

  • https://www.cvedetails.com/cve/CVE-2026-86060/


  • Published: Sat Sep 26 05:44:47 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us