The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on September 25, 2026: CVE-2026-65660 affecting Microsoft SharePoint (code injection) and CVE-2026-67279 impacting Mikrotik RouterOS (behavioral workflow enforcement flaw). These vulnerabilities are being actively exploited by threat actors and pose significant risks to federal enterprises and organizations worldwide. The addition reinforces CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets.

This incident highlights the ongoing challenge of vulnerability management in an era where threat actors rapidly weaponize newly disclosed flaws. With SharePoint being a critical collaboration platform and RouterOS powering networking infrastructure globally, these vulnerabilities represent prime targets for initial access, lateral movement, and potential ransomware deployment campaigns.

Why This Matters Now

Organizations face accelerated exploit timelines as threat actors increasingly target collaboration platforms and network infrastructure. The dual targeting of SharePoint and RouterOS demonstrates attackers' focus on high-value enterprise assets that can provide persistent access and broad network visibility.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CISA added CVE-2026-65660 (Microsoft SharePoint code injection) and CVE-2026-67279 (Mikrotik RouterOS behavioral workflow enforcement flaw) due to evidence of active exploitation.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this hybrid cloud attack by preventing unrestricted lateral movement and controlling egress paths. The segmented architecture could have reduced the blast radius from network device compromise to ransomware deployment.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The initial SharePoint compromise would likely still succeed, but CNSF segmentation would constrain the attacker's ability to reach adjacent cloud workloads and network resources from the compromised application tier.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Network device compromise may still occur, but Zero Trust segmentation would likely reduce the attacker's ability to leverage compromised network infrastructure for broad privilege escalation across cloud workloads and hybrid environments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between cloud environments and on-premises systems would likely be significantly constrained through encrypted east-west traffic inspection and policy enforcement that blocks unauthorized inter-environment communication paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control establishment would likely be constrained through comprehensive traffic visibility and policy enforcement that could detect and block unauthorized encrypted tunnel communications across multicloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration would likely be significantly reduced through controlled egress policies that restrict outbound data flows and monitor external communications from cloud workloads and compromised network paths.

Impact (Mitigations)

While some ransomware impact may still occur on initially compromised systems, the overall business disruption would likely be significantly reduced due to constrained lateral movement and limited blast radius across the hybrid infrastructure.

Impact at a Glance

Affected Business Functions

  • IT Infrastructure Management
  • Network Security
  • Document Management Systems
  • Enterprise Communications
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure varies by organization using affected Microsoft SharePoint and Mikrotik RouterOS systems. SharePoint vulnerabilities could expose corporate documents, collaboration data, and internal communications. RouterOS vulnerabilities could compromise network infrastructure and routing configurations.

Recommended Actions

  • • Implement inline IPS with signature-based detection to identify and block exploitation attempts against known CVEs like SharePoint code injection vulnerabilities
  • • Deploy zero trust segmentation with least privilege access controls to prevent lateral movement from compromised network devices to cloud resources
  • • Enable encrypted traffic inspection for east-west flows to detect and prevent unauthorized movement between on-premises and cloud environments
  • • Establish egress security with policy enforcement to monitor and control outbound traffic patterns and prevent data exfiltration to unauthorized destinations
  • • Implement multicloud visibility and control plane monitoring to detect anomalous interactions and suspicious automation across hybrid infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image