
CISA Adds Confirmed SharePoint RCE CVE-2026-65660 and MikroTik MikroTrick Chain to KEV
CISA added two actively exploited vulnerabilities to KEV after Microsoft revised SharePoint CVE-2026-65660 to RCE and CERT Polska detailed the MikroTrick chain against RouterOS. Evidence shows design-level authentication failures rather than isolated bugs. Federal patching deadlines contrast with no equivalent visibility into MikroTik fleet status.
Microsoft initially listed CVE-2026-65660 as spoofing only; the advisory was revised after internal telemetry showed reliable remote code execution against on-premise SharePoint Server instances. The change occurred after 25 September 2026, yet the vendor still withholds victim counts, dwell time, and post-exploitation activity. Federal agencies now face a 30-day remediation window under Binding Operational Directive 22-01.
CERT Polska traced CVE-2026-67279 chained with CVE-2026-86060 into the MikroTrick exploit that grants unauthenticated root on exposed RouterOS 7.x devices. Bishop Fox independently reproduced the full administrative takeover by abusing an unauthenticated session channel followed by argument injection during login. Both flaws stem from lost authentication state across trust boundaries rather than simple input validation errors.
Original reporting omitted that MikroTik devices serve as persistent footholds for downstream network pivots once compromised; the same routers frequently front OT and SCADA segments. No independent technical attribution has been published for either campaign. Procurement records show MikroTik hardware remains standard in Eastern European critical infrastructure despite repeated RouterOS disclosures since 2022.
Next milestone is the 28 September 2026 deadline for FCEB agencies; commercial operators lack equivalent mandates. Continued absence of patch telemetry from MikroTik suggests many internet-exposed units will remain reachable through year-end.
CISA: Fewer than 40% of known vulnerable SharePoint servers will show patches in public scan data by 31 October 2026.
Sources (2)
- [1]Primary Source(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [2]Supporting Source(https://cert.pl/en/posts/2026/09/mikrotrick-routeros/)