The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Microsoft SharePoint vulnerability, tracked as CVE-2026-65660 with a CVSS score of 8.8, and a Mikrotik RouterOS flaw to its Known Exploited Vulnerabilities catalog.
Active exploitation of SharePoint and Mikrotik vulnerabilities
- Active Exploitation Confirmed: Microsoft updated its advisory on Friday after gathering reliable evidence that CVE-2026-65660 is actively targeted in the wild.
- Critical Exposure Points: Impacted systems include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition (SE).
- Immediate Action Required: CERT.pl warns that Mikrotik instances facing unauthenticated SSH exploitation must be treated as fully compromised.
SharePoint Vulnerability Escalates to Active Exploitation
The security flaw designated as CVE-2026-65660 carries a CVSS severity rating of 8.8, classifying it as high-risk. Authenticated attackers with network access can inject and execute arbitrary malicious code due to insufficient input validation checks performed by the server. Microsoft originally addressed this weakness during the August patch cycle, assessing active exploitation as unlikely at the time.
That assessment shifted when Microsoft revised its advisory entry, confirming that reliable evidence now indicates active targeting by malicious actors. Enterprise environments running SharePoint Enterprise Server 2016, SharePoint Server 2019, or SharePoint Server Subscription Edition (SE) remain directly in the line of fire.
Mikrotik RouterOS Flaws and CERT.pl Warnings
Simultaneously, network infrastructure running Mikrotik RouterOS faces distinct threats. Mikrotik issued security advisories regarding an SSH code defect tracked as CVE-2026-67279, which carries a CVSS score of 6.9. The flaw allows unauthenticated remote attackers to create, overwrite, or restore files on vulnerable devices.
CERT.pl identified an attack chain dubbed “MikroTrick,” which combines CVE-2026-67279 with CVE-2026-86060. Attackers use open SSH access to seize full administrative control over affected routers. Administrators are advised to inspect exposed hardware for unauthorized modifications, unexpected user accounts, or signs of compromise.
Indicators of Compromise and Ongoing Threats
Investigations into the Mikrotik attacks reveal specific forensic artifacts. CERT.pl highlighted the creation of a high-privileged user account named “ops” alongside recurring log anomalies such as login failures for user “-2” via SSH and user additions originating from the same identifier. Attack traffic has been traced to IP addresses including 82.192.72.4 and 103.102.31.18, with malicious scanning and exploitation observed since early September.
| Vendor & Product | CVE Identifier | CVSS Score | Affected Versions |
|---|---|---|---|
| Microsoft SharePoint | CVE-2026-65660 | 8.8 (High) | Server 2016, 2019, SE |
| Mikrotik RouterOS | CVE-2026-67279 | 6.9 (Medium) | Selected 6.x and 7.x releases |
Beyond SharePoint and Mikrotik hardware, infrastructure security teams are confronting parallel threats targeting enterprise web infrastructure. Recent reports from the weekend confirm that popular products from other vendors, including Citrix Netscaler ADC and gateways, have also drawn focused attention from cybercriminal syndicates.
Remediation Protocols for Enterprise Networks
Organizations operating unpatched SharePoint installations or Mikrotik routers must act without delay. For RouterOS, critical updates are available in software branches including versions 7.25 Beta 3, 7.24.2, 7.23.4, and 6.49.21. Security analysts recommend treating any unpatched legacy instance as a total loss until comprehensive forensic audits verify system integrity.