Executive Summary
In September 2026, CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wild. CVE-2026-65660, a remote code execution flaw in Microsoft SharePoint Server initially misclassified as a spoofing vulnerability, allows authenticated attackers to execute arbitrary code over the network. Simultaneously, CVE-2026-67279 affecting MikroTik RouterOS was chained with CVE-2026-86060 in an exploit dubbed 'MikroTrick' to achieve complete administrative takeover of internet-exposed routers without authentication. Microsoft confirmed reliable evidence of attacks against SharePoint but has not disclosed attribution, scope, or impact details.
These incidents highlight the growing sophistication of threat actors exploiting trust boundary failures and authentication bypass vulnerabilities to gain initial access to critical infrastructure components.
Why This Matters Now
Organizations face immediate risk from actively exploited vulnerabilities in widely deployed enterprise platforms, with attackers increasingly targeting authentication and trust boundary failures to establish persistent footholds in corporate networks.
Attack Path Analysis
Attackers exploited CVE-2026-65660 in Microsoft SharePoint to achieve remote code execution, then escalated privileges within the SharePoint environment. They moved laterally to MikroTik RouterOS devices using the MikroTrick exploit chain (CVE-2026-67279 + CVE-2026-86060) to gain full administrative control without authentication. Command and control was established through compromised network infrastructure, enabling data exfiltration from internal systems. The attack culminated in potential business disruption through compromised network infrastructure and unauthorized access to sensitive data.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2026-65660 code injection vulnerability in Microsoft SharePoint Server to achieve remote code execution through network-based attack
Related CVEs
CVE-2026-65660
CVSS 8.8A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
Affected Products:
Microsoft SharePoint Server – Multiple versions
Exploit Status:
exploited in the wildCVE-2026-67279
CVSS 6.5An improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request.
Affected Products:
MikroTik RouterOS – 7.x builds
Exploit Status:
exploited in the wildCVE-2026-86060
CVSS 9.8An argument injection flaw in the MikroTik RouterOS login process that enables full administrative access when chained with CVE-2026-67279.
Affected Products:
MikroTik RouterOS – 7.x builds
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Valid Accounts
Exploitation for Privilege Escalation
Impair Defenses
Process Injection
External Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST Cybersecurity Framework 2.0 – Asset Vulnerabilities are Identified and Documented
Control ID: ID.RA-01
PCI DSS 4.0 – Software Security Patches are Applied Within One Month
Control ID: 6.2.3
CISA Zero Trust Maturity Model 2.0 – Multi-Factor Authentication for All Users
Control ID: AC.L2-01
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.02(g)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
CISA KEV additions indicate active exploitation of SharePoint RCE and RouterOS vulnerabilities affecting federal agencies with September 28th remediation deadline.
Information Technology/IT
SharePoint code injection and RouterOS authentication bypass vulnerabilities expose IT infrastructure to remote code execution requiring immediate patching and segmentation.
Telecommunications
MikroTik RouterOS exploitation enables full administrative control of network infrastructure, compromising carrier-grade routing equipment and customer traffic security.
Financial Services
Remote code execution vulnerabilities in collaboration platforms and network equipment threaten compliance with PCI DSS and data protection requirements.
Sources
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wildhttps://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.htmlVerified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Microsoft Security Response Center Advisory CVE-2026-65660https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65660Verified
- MikroTrick Technical Analysis by CERT Polskahttps://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/Verified
- MikroTrick: Inside the RouterOS Takeover Chainhttps://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chainVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack's blast radius by constraining lateral movement between SharePoint systems and network infrastructure through microsegmentation and east-west traffic controls. The segmented architecture could limit attacker reach across cloud and on-premises environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The SharePoint compromise would likely still occur, but CNSF microsegmentation may constrain the attacker's ability to reach additional cloud workloads and services from the initially compromised system.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation within SharePoint may still succeed, but Zero Trust segmentation would likely constrain the elevated privileges to specific workload boundaries rather than broader system or network access.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain or block the lateral movement from SharePoint systems to MikroTik RouterOS devices by restricting inter-segment communication paths and protocols.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may detect and constrain command and control traffic patterns across hybrid environments, limiting the attacker's ability to coordinate activities between compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration attempts by enforcing policy-based restrictions on outbound traffic flows, even from compromised network infrastructure components with administrative privileges.
While some business disruption may still occur from compromised systems, the overall impact scope would likely be reduced through constrained lateral reach and limited access to critical cloud workloads and data repositories.
Impact at a Glance
Affected Business Functions
- Enterprise Collaboration Platforms
- Network Infrastructure Management
- Remote Access Services
- Administrative Control Systems
Estimated downtime: 7 days
Estimated loss: N/A
Potential unauthorized access to SharePoint document libraries, corporate communications, and complete administrative control over network routing infrastructure including configuration data and network traffic routing capabilities
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block known exploit patterns for CVE-2026-65660 and MikroTrick exploit chains before they reach vulnerable applications
- • Deploy zero trust segmentation with least privilege policies to prevent lateral movement from compromised SharePoint servers to network infrastructure devices like RouterOS
- • Establish egress security and policy enforcement to detect and block unauthorized data exfiltration attempts through compromised network devices
- • Enable multicloud visibility and control with centralized policy enforcement to detect anomalous interactions and suspicious automation targeting infrastructure components
- • Deploy cloud native security fabric (CNSF) with real-time inspection and distributed policy enforcement to provide autonomous protection against multi-stage exploit chains



