⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

September 26, 2026

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild Ravie LakshmananSep 26, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows – CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network. CVE-2026-67279 (CVSS score: 6.9) – An improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request. As reported by The Hacker News earlier…

CVEs: CVE-2026-65660, CVE-2026-67279, CVE-2026-86060