INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SharePoint RCE and RouterOS Flaws Exploited in the Wild

| 2026-09-26 08:49 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability CVE-2026-65660 in Microsoft SharePoint Server has been linked to a code injection attack, allowing unauthorized access and potential remote code execution. This exploit was first reported by The Hacker News earlier this week, citing an updated advisory from Microsoft that could be abused for such purposes. The vulnerabilities have since been chained along with another flaw CVE-2026-86060 in RouterOS login process as part of an exploit codenamed MikroTrick. These flaws were added to the Known Exploited Vulnerabilities (KEV) catalog by CISA on September 11, 2026, and are currently being actively exploited in the wild.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent code injection vulnerabilities, such as using input validation and sanitization techniques. * Regularly update and patch Microsoft SharePoint Server and Mikrotik RouterOS to ensure that known exploits are addressed before they can be used against the systems. * Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent unauthorized access attempts, including those related to code injection vulnerabilities. * Conduct regular security audits and penetration testing to identify potential weaknesses in Microsoft SharePoint Server and Mikrotik RouterOS, and implement remediation measures as needed.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-65660CVE-2026-65660 CVE-2026-67279CVE-2026-67279 CVE-2026-86060CVE-2026-86060
Target & Sectors
Global Scope
Incident Timeline
‎September 2, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the General Document Context of Microsoft SharePoint 2016 running on an affected MikroTik RouterOS instance.
‎September 11, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the wild to target MikroTik routers running RouterOS.
vulnerability CVE-2026-86060
‎September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog on September 25, 2026.
attribution Microsoft SharePoint
attribution Mikrotik RouterOS
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎Sep 26, 2026
Threat actors used a combination of the CVE-2026-65660 and CVE-2026-67279 vulnerabilities in Microsoft Office SharePoint to exploit full unauthenticated access to the administrative console.
organisation Microsoft
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
organisation CVE-2026-67279
organisation KEV
organisation CVE-2026
infrastructure Windows
organisation MikroTik RouterOS
organisation MikroTrick
organisation RouterOS
‎2016, 2019
Threat actors exploited a Remote Code Execution (RCE) vulnerability in SharePoint Server 2016 and its later versions, targeting MikroTik routers running RouterOS.
tactic T1584.004 - Server
‎2026/09/26
MikroTik RouterOS and Microsoft SharePoint were found to have two active exploits in the wild.
organisation MikroTik RouterOS
organisation SSH
organisation SharePoint RCE
data_breach 2 September
‎September 28, 2026
Threat actors exploited a Remote Code Execution (RCE) vulnerability in the General Document Context of SharePoint, combined with a flaw in MikroTik RouterOS.
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
2
September