CISA has added vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The additions cover CVE-2026-65660 in SharePoint and CVE-2026-67279 in RouterOS, according to reporting by The Hacker News.

CVE-2026-65660 is described as a SharePoint code-injection vulnerability that can allow an authorized attacker to execute code over a network. Microsoft said it had reliable evidence of observed attacks as of September 25. CISA’s inclusion means affected organizations should treat the issue as an urgent remediation priority.

The RouterOS issue has been chained with CVE-2026-86060 in an exploit dubbed MikroTrick. CERT Polska said the chain can result in full unauthenticated access to the administrative console on susceptible internet-exposed routers. The reporting notes that federal civilian executive-branch agencies have a September 28 deadline to apply the necessary fixes.

Security teams should inventory SharePoint and RouterOS assets, identify exposed systems, apply vendor fixes, and review authentication, administrative and network telemetry for suspicious activity. Organizations should also check CISA’s KEV entry and the relevant vendor advisories for authoritative remediation details.

Source: The Hacker News, “SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild”.

By Allan