Exploited SharePoint and MikroTik router flaws get a 28 September federal deadline
EditorialBy TrustList Editorial
CISA lists SharePoint Server flaw CVE-2026-65660, first rated a moderate spoofing bug, and MikroTik RouterOS SSH flaw CVE-2026-67279 as exploited. Both were fixed weeks ago; unpatched servers and routers are the target.
About Exploited SharePoint and MikroTik router flaws get a 28 September federal deadline
Exploited SharePoint and MikroTik router flaws get a 28 September federal deadline
25 September 2026 — The US Cybersecurity and Infrastructure Security Agency (CISA) added two flaws to its Known Exploited Vulnerabilities catalogue on 25 September 2026: CVE-2026-65660 in on-premises Microsoft SharePoint Server, and CVE-2026-67279 in MikroTik RouterOS, the operating system of MikroTik's routers and switches. US federal agencies must fix both by Monday 28 September. For other organisations the catalogue is the most reliable public list of flaws attackers are known to be using, and both fixes have been available for weeks.
The SharePoint flaw was first rated moderate
Microsoft fixed CVE-2026-65660 in its 11 August 2026 updates, but described it as a spoofing flaw rated 6.5 out of 10. The public CVE record describes it as code injection that lets any signed-in user, even one with low privileges, run code on the server, and the US vulnerability database scores it 8.8. The Hacker News reported the gap on 22 September, when a researcher published full technical details; at that point no attacks had been reported. Two days later, on 24 September, the Canadian Centre for Cyber Security issued alert AL26-023 saying the flaw is being exploited, and that combined with other SharePoint flaws it allows code execution without a login on servers that permit anonymous access. The sources therefore differ on timing: exploitation was reported within two days of the technical write-up.
Fixed builds, per the Canadian alert, are 16.0.5565.1001 for SharePoint Enterprise Server 2016, 16.0.10417.20198 for SharePoint Server 2019 and 16.0.19725.20522 for Subscription Edition. The same alert notes that the 2016 and 2019 versions reached end of support in July 2026. SharePoint Online is not affected.
The MikroTik flaw is part of the "MikroTrick" chain
CVE-2026-67279 lets a client that has never logged in open an SSH session channel on a RouterOS device and send it commands. CISA's entry notes that it chains with a second flaw, CVE-2026-86060, to give full administrator access. MikroTik published fixes on 3 September; CERT Polska, which disclosed six RouterOS flaws on 5 September, says the chain has been used against devices since at least 2 September. SecurityWeek reported that the Shadowserver Foundation counted more than 120,000 MikroTik devices with SSH reachable from the internet.
Fixed releases are 6.49.21, 7.23.4 and 7.24.2. CERT Polska lists one further flaw in the same set, CVE-2026-67278, as fixed only in 7.23.6 and 7.24.3, so the newest release in each branch is the safer target.
Who is affected
Organisations running SharePoint Server on their own servers or through a hosting partner, and anyone with MikroTik equipment, which is common in branch offices, small businesses and internet service providers. Managed network and IT providers often run both on a customer's behalf.
What to do
- Check every SharePoint Server farm against the build numbers above. Where 2016 or 2019 is still in use, plan the move off an unsupported version.
- Review SharePoint for web shells, new administrator accounts and unexplained changes since August.
- Upgrade every RouterOS device to the newest release in its branch, and stop exposing SSH and other management ports to the internet.
- After upgrading, check each device for unknown users, scripts or settings; SecurityWeek reported attackers creating an account named "ops".
- If a provider runs these systems for you, ask in writing for the version installed and the date it was applied.
Sources
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog — 25 September 2026
- CISA Known Exploited Vulnerabilities catalogue, JSON feed (read 26 September 2026) — 26 September 2026
- Canadian Centre for Cyber Security: AL26-023, Vulnerability impacting Microsoft SharePoint Server, CVE-2026-65660 — 24 September 2026
- The Hacker News: SharePoint flaw initially listed as spoofing by Microsoft enables authenticated RCE — 22 September 2026
- MikroTik: September 2026 vulnerability summary — 3 September 2026
- CERT Polska: Vulnerabilities in MikroTik RouterOS software — 5 September 2026
- SecurityWeek: MikroTik patches critical flaws chained to hack routers — 8 September 2026
- BleepingComputer: CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacks — 25 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.