{"id":3181,"date":"2026-09-26T11:55:52","date_gmt":"2026-09-26T11:55:52","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3181"},"modified":"2026-09-26T11:55:52","modified_gmt":"2026-09-26T11:55:52","slug":"sharepoint-rce-and-mikrotik-routeros-flaws-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3181","title":{"rendered":"SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 26, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/\u00a0Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiHEPamtRBBEzltsUWnj-F8umrMf4eUUhTmGUJdhHlrvWZamHWpBtXcrpQKDArTziRiiIWv8psX4DTZyN9kLBtcAyLOPJma9_M7sYKgYz6WBISbOhJrRlfByfCKfTTMdBqaYUp-0nskrt2ndt3poUFLDGegEFJojS0EzEvwAqzaUNtvX26jZopYE4zA4S3K\/s1700-nu-rw-lo-l85-e365\/share-kev.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/25\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">added<\/a> two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, citing evidence of active exploitation.<\/p>\n<p>The vulnerabilities in question are as follows &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-65660<\/strong> (CVSS score: 8.8) &#8211; A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.<\/li>\n<li><strong>CVE-2026-67279<\/strong> (CVSS score: 6.9) &#8211; An improper enforcement of behavioral workflow vulnerability in  Mikrotik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request.<\/li>\n<\/ul>\n<p>As reported by The Hacker News earlier this week, CVE-2026-65660 was originally described by Microsoft as a <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/8\/11\/the-august-2026-security-update-review\" target=\"_blank\">spoofing vulnerability<\/a> impacting SharePoint Server. The tech giant has since updated the advisory to state that it could be abused to obtain remote code execution.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abAs of 9\/25\/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability,\u00bb the Windows maker <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-65660\" target=\"_blank\">noted<\/a>.<\/p>\n<p>Microsoft hasn&#8217;t disclosed who was behind the exploitation efforts, when they started, how many organizations have been targeted, how many of them have been successful, and what attackers did once inside the vulnerable service.<\/p>\n<p>The second vulnerability to be added to the KEV catalog is CVE-2026-67279, which has been chained along with CVE-2026-86060, an argument injection flaw in the RouterOS login process, as part of an exploit codenamed <b><a href=\"https:\/\/thehackernews.com\/2026\/09\/mikrotrick-chain-let-attackers-take.html\" target=\"_blank\">MikroTrick<\/b>.<\/p>\n<p>The exploit chain has been employed to take full administrative control of internet-exposed susceptible routers without the need for a password, per CERT Polska.<\/p>\n<p>\u00abCombining the two vulnerabilities resulted in full unauthenticated access to the administrative console,\u00bb the Polish cybersecurity agency <a href=\"https:\/\/cert.pl\/en\/posts\/2026\/09\/mikrotrick-technical-analysis\/\" target=\"_blank\">said<\/a>. \u00abCVE-2026-67279 allowed an unauthenticated client to create a session channel, while CVE-2026-86060 allowed it to supply login with an attacker-controlled policy mask.\u00bb<\/p>\n<p>In a separate analysis, Bishop Fox said it was able to reproduce the complete administrative takeover on vulnerable RouterOS 7.x builds.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abMikroTrick combines two failures at different trust boundaries,\u00bb security researcher  Emilio Gallegos <a href=\"https:\/\/bishopfox.com\/blog\/mikrotrick-inside-the-routeros-takeover-chain\" target=\"_blank\">said<\/a>. \u00abThe first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login. The second causes the login process to treat data from that connection as a trusted administrative identity.\u00bb<\/p>\n<p>\u00abMikroTrick exposes a design risk in privileged software: a feature intended only for trusted local callers becomes a remote attack surface when an upstream component loses track of authentication state.\u00bb <\/p>\n<p>It&#8217;s worth noting that CISA added CVE-2026-86060 to its KEV catalog on September 11, 2026. Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 26, 2026Vulnerability \/\u00a0Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3182,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[201,128,11,3322,316,3396,751,656],"class_list":["post-3181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actively","tag-exploited","tag-flaws","tag-mikrotik","tag-rce","tag-routeros","tag-sharepoint","tag-wild"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3181"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3181\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3182"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}