Executive Summary
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on September 25, 2026: CVE-2026-65660 affecting Microsoft SharePoint (code injection) and CVE-2026-67279 impacting Mikrotik RouterOS (behavioral workflow enforcement flaw). These vulnerabilities are being actively exploited by threat actors and pose significant risks to federal enterprises and organizations worldwide. The addition reinforces CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets.
This incident highlights the ongoing challenge of vulnerability management in an era where threat actors rapidly weaponize newly disclosed flaws. With SharePoint being a critical collaboration platform and RouterOS powering networking infrastructure globally, these vulnerabilities represent prime targets for initial access, lateral movement, and potential ransomware deployment campaigns.
Why This Matters Now
Organizations face accelerated exploit timelines as threat actors increasingly target collaboration platforms and network infrastructure. The dual targeting of SharePoint and RouterOS demonstrates attackers' focus on high-value enterprise assets that can provide persistent access and broad network visibility.
Attack Path Analysis
Attackers exploit CVE-2026-65660 SharePoint code injection to establish foothold, then leverage CVE-2026-67279 RouterOS vulnerability for network device compromise and privilege escalation. From compromised network infrastructure, attackers perform lateral movement across hybrid environments, establish persistent command and control channels through encrypted tunnels, exfiltrate sensitive data through unmonitored egress paths, and deploy ransomware to maximize business impact.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2026-65660 Microsoft SharePoint code injection vulnerability on publicly exposed SharePoint instances to gain initial access
Related CVEs
CVE-2026-65660
CVSS 8.8A code injection vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code on the server.
Affected Products:
Microsoft SharePoint Server – Multiple versions
Exploit Status:
exploited in the wildCVE-2026-67279
CVSS 6.5An improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS allows attackers to bypass security controls.
Affected Products:
Mikrotik RouterOS – Multiple versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Process Injection
Ingress Tool Transfer
Web Shell
Valid Accounts
Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Vulnerability Management
Control ID: 6.2.2
CISA Zero Trust Maturity Model 2.0 – Asset Management and Visibility
Control ID: Application Security-AS.AM.1
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.16
Digital Operational Resilience Act (DORA) – ICT Risk Management
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical exposure to SharePoint and RouterOS vulnerabilities requiring immediate remediation under BOD 26-04 compliance mandates.
Information Technology/IT
IT infrastructure providers managing SharePoint deployments and Mikrotik routing equipment face elevated risk from active exploitation campaigns targeting core systems.
Financial Services
Banking institutions using SharePoint for document management and Mikrotik networking equipment require urgent vulnerability patching to prevent data exfiltration.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance risks from SharePoint code injection and router vulnerabilities potentially exposing protected health information.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskhttps://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-riskVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this hybrid cloud attack by preventing unrestricted lateral movement and controlling egress paths. The segmented architecture could have reduced the blast radius from network device compromise to ransomware deployment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial SharePoint compromise would likely still succeed, but CNSF segmentation would constrain the attacker's ability to reach adjacent cloud workloads and network resources from the compromised application tier.
Control: Zero Trust Segmentation
Mitigation: Network device compromise may still occur, but Zero Trust segmentation would likely reduce the attacker's ability to leverage compromised network infrastructure for broad privilege escalation across cloud workloads and hybrid environments.
Control: East-West Traffic Security
Mitigation: Lateral movement between cloud environments and on-premises systems would likely be significantly constrained through encrypted east-west traffic inspection and policy enforcement that blocks unauthorized inter-environment communication paths.
Control: Multicloud Visibility & Control
Mitigation: Command and control establishment would likely be constrained through comprehensive traffic visibility and policy enforcement that could detect and block unauthorized encrypted tunnel communications across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration would likely be significantly reduced through controlled egress policies that restrict outbound data flows and monitor external communications from cloud workloads and compromised network paths.
While some ransomware impact may still occur on initially compromised systems, the overall business disruption would likely be significantly reduced due to constrained lateral movement and limited blast radius across the hybrid infrastructure.
Impact at a Glance
Affected Business Functions
- IT Infrastructure Management
- Network Security
- Document Management Systems
- Enterprise Communications
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure varies by organization using affected Microsoft SharePoint and Mikrotik RouterOS systems. SharePoint vulnerabilities could expose corporate documents, collaboration data, and internal communications. RouterOS vulnerabilities could compromise network infrastructure and routing configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with signature-based detection to identify and block exploitation attempts against known CVEs like SharePoint code injection vulnerabilities
- • Deploy zero trust segmentation with least privilege access controls to prevent lateral movement from compromised network devices to cloud resources
- • Enable encrypted traffic inspection for east-west flows to detect and prevent unauthorized movement between on-premises and cloud environments
- • Establish egress security with policy enforcement to monitor and control outbound traffic patterns and prevent data exfiltration to unauthorized destinations
- • Implement multicloud visibility and control plane monitoring to detect anomalous interactions and suspicious automation across hybrid infrastructure



