Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Pennsylvania measles outbreak spreads, with 55 new cases reported since Wednesday | Pennsylvania

    September 26, 2026

    12 Best White Elephant Gifts, Plus a Prank Box to Put Them In (2026)

    September 26, 2026

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Pennsylvania measles outbreak spreads, with 55 new cases reported since Wednesday | Pennsylvania
    • 12 Best White Elephant Gifts, Plus a Prank Box to Put Them In (2026)
    • OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
    • Kraken’s parent Payward is building a financial empire that goes far beyond crypto trading
    • After a Deadly Flood, What Does Climate Justice for Nepal Look Like?
    • Milwaukee Police Department considers use of generative AI
    • Look again – there’s more to Europe’s election trends than far-right success | Cas Mudde
    • Is Ethiopia on the verge of another civil war as fighting erupts in Tigray? | Conflict News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 26, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 26, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The vulnerabilities in question are as follows –

    • CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
    • CVE-2026-67279 (CVSS score: 6.9) – An improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request.

    As reported by The Hacker News earlier this week, CVE-2026-65660 was originally described by Microsoft as a spoofing vulnerability impacting SharePoint Server. The tech giant has since updated the advisory to state that it could be abused to obtain remote code execution.

    Cybersecurity

    “As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability,” the Windows maker noted.

    Microsoft hasn’t disclosed who was behind the exploitation efforts, when they started, how many organizations have been targeted, how many of them have been successful, and what attackers did once inside the vulnerable service.

    The second vulnerability to be added to the KEV catalog is CVE-2026-67279, which has been chained along with CVE-2026-86060, an argument injection flaw in the RouterOS login process, as part of an exploit codenamed MikroTrick.

    The exploit chain has been employed to take full administrative control of internet-exposed susceptible routers without the need for a password, per CERT Polska.

    “Combining the two vulnerabilities resulted in full unauthenticated access to the administrative console,” the Polish cybersecurity agency said. “CVE-2026-67279 allowed an unauthenticated client to create a session channel, while CVE-2026-86060 allowed it to supply login with an attacker-controlled policy mask.”

    In a separate analysis, Bishop Fox said it was able to reproduce the complete administrative takeover on vulnerable RouterOS 7.x builds.

    Cybersecurity

    “MikroTrick combines two failures at different trust boundaries,” security researcher Emilio Gallegos said. “The first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login. The second causes the login process to treat data from that connection as a trusted administrative identity.”

    “MikroTrick exposes a design risk in privileged software: a feature intended only for trusted local callers becomes a remote attack surface when an upstream component loses track of authentication state.”

    It’s worth noting that CISA added CVE-2026-86060 to its KEV catalog on September 11, 2026. Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.

    actively Exploited flaws MikroTik RCE RouterOS SharePoint wild
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Rydox marketplace admin pleads guilty, faces 22 years in prison

    Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

    Microsoft plans to deprecate Windows Deployment Services

    Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Pennsylvania measles outbreak spreads, with 55 new cases reported since Wednesday | Pennsylvania

    September 26, 2026

    12 Best White Elephant Gifts, Plus a Prank Box to Put Them In (2026)

    September 26, 2026

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    September 26, 2026

    Kraken’s parent Payward is building a financial empire that goes far beyond crypto trading

    September 26, 2026
    Latest Posts

    5 Best AI Notetakers (2026), Tested and Reviewed

    August 6, 2026

    All schools to get pupil attendance targets, government says

    August 6, 2026

    Trump vows to find ‘leakers’ after reports of depleted Iran war munitions | US-Israel war on Iran News

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Pennsylvania measles outbreak spreads, with 55 new cases reported since Wednesday | Pennsylvania

    September 26, 2026

    12 Best White Elephant Gifts, Plus a Prank Box to Put Them In (2026)

    September 26, 2026

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.