Home › Intelligence › Brief
VULNERABILITY BRIEF 🟠 High Advisory

CISA Adds Critical SharePoint Code Injection (CVE-2026-65660) and MikroTik RouterOS SSH Bypass (CVE-2026-67279) to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high‑severity vulnerabilities—Microsoft SharePoint Server code‑injection (CVE‑2026‑65660) and MikroTik RouterOS SSH bypass (CVE‑2026‑67279)—to its Known Exploited Vulnerabilities catalog. Both are being actively leveraged in the wild, prompting mandatory remediation deadlines for federal agencies and a strong recommendation for private organizations. The inclusion underscores the need for continuous vulnerability monitoring and demonstrable remediation evidence to satisfy audit and trust requirements.

Verisq™ Intelligence · 📅 September 26, 2026 · 📰 securityaffairs.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Code Injection in Microsoft SharePoint (CVE‑2026‑65660) and SSH Bypass in MikroTik RouterOS (CVE‑2026‑67279) Added to CISA KEV Catalog

What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed two high‑severity flaws into its Known Exploited Vulnerabilities (KEV) catalog: a remote code‑injection issue in Microsoft SharePoint Server (CVE‑2026‑65660, CVSS 8.8) and an unauthenticated SSH‑bypass in MikroTik RouterOS (CVE‑2026‑67279, CVSS 6.9).

Exploitability – Both vulnerabilities are confirmed to be actively exploited in the wild. The SharePoint flaw requires a low‑privileged authenticated user, while the RouterOS bug can be leveraged without credentials and has been chained with CVE‑2026‑86060 to obtain full admin access.

Affected Products – Microsoft SharePoint Server 2016, 2019, and Subscription Edition; MikroTik RouterOS (all supported versions).

Why It Matters for Trust & Control Assurance

  • Continuous vulnerability monitoring is a core control objective; the KEV listing signals that failure to remediate is a measurable risk gap across most frameworks.
  • Demonstrable evidence of patching or mitigation satisfies auditors looking for “defensible” remediation trails.
  • Federal directive BOD 22‑01 forces agencies to close the gap by 28 Sept 2026, and private firms are urged to follow suit to maintain a trustworthy security posture.

Recommended Actions

  1. Prioritize patching SharePoint Server and updating RouterOS to the vendor‑released fixes.
  2. Run authenticated scans (e.g., credentialed Nessus, Qualys) to confirm remediation.
  3. Capture remediation tickets, patch‑install logs, and scan results as evidence for your control‑mapping repository.
  4. Align the remediation effort with the “Vulnerability Management” control area in your chosen framework (e.g., NIST CSF ID.RA‑1).

Source: SecurityAffairs article

📰 Original Source
https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →