INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SharePoint RCE and RouterOS Flaws Exploited in the Wild
| 2026-09-26 08:49 CRITICAL HIGHExecutive Summary AI-generated
The vulnerability CVE-2026-65660 in Microsoft SharePoint Server has been linked to a code injection attack, allowing unauthorized access and potential remote code execution. This exploit was first reported by The Hacker News earlier this week, citing an updated advisory from Microsoft that could be abused for such purposes. The vulnerabilities have since been chained along with another flaw CVE-2026-86060 in RouterOS login process as part of an exploit codenamed MikroTrick. These flaws were added to the Known Exploited Vulnerabilities (KEV) catalog by CISA on September 11, 2026, and are currently being actively exploited in the wild.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent code injection vulnerabilities, such as using input validation and sanitization techniques.
* Regularly update and patch Microsoft SharePoint Server and Mikrotik RouterOS to ensure that known exploits are addressed before they can be used against the systems.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent unauthorized access attempts, including those related to code injection vulnerabilities.
* Conduct regular security audits and penetration testing to identify potential weaknesses in Microsoft SharePoint Server and Mikrotik RouterOS, and implement remediation measures as needed.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-65660CVE-2026-65660
CVE-2026-67279CVE-2026-67279
CVE-2026-86060CVE-2026-86060
Target & Sectors
Global Scope
Incident Timeline
September 2, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the General Document Context of Microsoft SharePoint 2016 running on an affected MikroTik RouterOS instance.
September 11, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the wild to target MikroTik routers running RouterOS.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-86060
It's worth noting that CISA
added
CVE-2026-86060 to its KEV catalog on September 11, 2026.
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog on September 25, 2026.
Click on any entity below to view its context and source!
attribution
Microsoft SharePoint
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
attribution
Mikrotik RouterOS
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
Sep 26, 2026
Threat actors used a combination of the CVE-2026-65660 and CVE-2026-67279 vulnerabilities in Microsoft Office SharePoint to exploit full unauthenticated access to the administrative console.
Click on any entity below to view its context and source!
organisation
Microsoft
As
reported
by The Hacker News earlier this week, CVE-2026-65660 was originally described by Microsoft as a
spoofing vulnerability
impacting SharePoint Server.
infrastructure
Microsoft Office
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
Microsoft Office SharePoint
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
CVE-2026-67279
CVE-2026-67279
(CVSS score: 6.9) -
organisation
KEV
The second vulnerability to be added to the KEV catalog is CVE-2026-67279, which has been chained along with CVE-2026-86060, an argument injection flaw in the RouterOS login process, as part of an exploit codenamed
MikroTrick
.
organisation
CVE-2026
"CVE-2026-67279 allowed an unauthenticated client to create a session channel, while CVE-2026-86060 allowed it to supply login with an attacker-controlled policy mask.
infrastructure
Windows
"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the Windows maker
noted
.
organisation
MikroTik RouterOS
An improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request.
organisation
MikroTrick
"MikroTrick combines two failures at different trust boundaries," security researcher Emilio Gallegos
said
.
organisation
RouterOS
"The first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login.
2016, 2019
Threat actors exploited a Remote Code Execution (RCE) vulnerability in SharePoint Server 2016 and its later versions, targeting MikroTik routers running RouterOS.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
The flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
2026/09/26
MikroTik RouterOS and Microsoft SharePoint were found to have two active exploits in the wild.
Click on any entity below to view its context and source!
organisation
MikroTik RouterOS
The second flaw added to the catalog, tracked as
CVE-2026-67279
(CVSS score of 6.9), is an SSH protocol flaw in MikroTik RouterOS that allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel and execute commands, potentially creating or modifying files on the device.
SharePoint RCE and MikroTik RouterOS
organisation
SSH
The second flaw added to the catalog, tracked as
CVE-2026-67279
(CVSS score of 6.9), is an SSH protocol flaw in MikroTik RouterOS that allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel and execute commands, potentially creating or modifying files on the device.
organisation
SharePoint RCE
SharePoint RCE and MikroTik RouterOS
data_breach
2 September
CERT Polska reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain.
September 28, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the General Document Context of SharePoint, combined with a flaw in MikroTik RouterOS.
Click on any entity below to view its context and source!
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.
Tactical Metrics
Metrics
infrastructure
Microsoft Office
Affected Product
Click for context!
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
Metrics
infrastructure
Windows
Affected Product
"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the Windows maker
noted
.
Metrics
data_breach
2
September
CERT Polska reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain.
Intelligence Sources
Security Affairs
2026-09-25
The Hacker News
2026-09-26
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-27T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
attribution
Attributing Entity
Flaws Actively Exploited
authority
10x
organisation
Identified Entity
Microsoft
entity
8x
timeline
Temporal Reference
Sep 26, 2026
date
3x
vulnerability
Exploited CVE
CVE-2026-65660
cve
2x
tactic
Cyber Operation Type
Spoofing
tactic
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
infrastructure
Affected Product
Microsoft Office
software
2x
vulnerability
CVSS Score
9
score
Contextual Telemetry
Context Block
6 METRICS
general metric
Score
9
score
general metric
Cvss Score
7
cvss score
general metric
Sep
26
sep
source region
Origin Country
Poland
country
general metric
Improper Enforcement
65,660
improper enforcement
data breach
September
2
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.