The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wild. CVE-2026-65660, a remote code execution flaw in Microsoft SharePoint Server initially misclassified as a spoofing vulnerability, allows authenticated attackers to execute arbitrary code over the network. Simultaneously, CVE-2026-67279 affecting MikroTik RouterOS was chained with CVE-2026-86060 in an exploit dubbed 'MikroTrick' to achieve complete administrative takeover of internet-exposed routers without authentication. Microsoft confirmed reliable evidence of attacks against SharePoint but has not disclosed attribution, scope, or impact details.

These incidents highlight the growing sophistication of threat actors exploiting trust boundary failures and authentication bypass vulnerabilities to gain initial access to critical infrastructure components.

Why This Matters Now

Organizations face immediate risk from actively exploited vulnerabilities in widely deployed enterprise platforms, with attackers increasingly targeting authentication and trust boundary failures to establish persistent footholds in corporate networks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Originally misclassified as a spoofing vulnerability, it actually enables remote code execution and Microsoft has confirmed active exploitation with reliable evidence of attacks in the wild.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the attack's blast radius by constraining lateral movement between SharePoint systems and network infrastructure through microsegmentation and east-west traffic controls. The segmented architecture could limit attacker reach across cloud and on-premises environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The SharePoint compromise would likely still occur, but CNSF microsegmentation may constrain the attacker's ability to reach additional cloud workloads and services from the initially compromised system.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation within SharePoint may still succeed, but Zero Trust segmentation would likely constrain the elevated privileges to specific workload boundaries rather than broader system or network access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely constrain or block the lateral movement from SharePoint systems to MikroTik RouterOS devices by restricting inter-segment communication paths and protocols.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls may detect and constrain command and control traffic patterns across hybrid environments, limiting the attacker's ability to coordinate activities between compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely constrain data exfiltration attempts by enforcing policy-based restrictions on outbound traffic flows, even from compromised network infrastructure components with administrative privileges.

Impact (Mitigations)

While some business disruption may still occur from compromised systems, the overall impact scope would likely be reduced through constrained lateral reach and limited access to critical cloud workloads and data repositories.

Impact at a Glance

Affected Business Functions

  • Enterprise Collaboration Platforms
  • Network Infrastructure Management
  • Remote Access Services
  • Administrative Control Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential unauthorized access to SharePoint document libraries, corporate communications, and complete administrative control over network routing infrastructure including configuration data and network traffic routing capabilities

Recommended Actions

  • • Implement inline IPS with Suricata signatures to detect and block known exploit patterns for CVE-2026-65660 and MikroTrick exploit chains before they reach vulnerable applications
  • • Deploy zero trust segmentation with least privilege policies to prevent lateral movement from compromised SharePoint servers to network infrastructure devices like RouterOS
  • • Establish egress security and policy enforcement to detect and block unauthorized data exfiltration attempts through compromised network devices
  • • Enable multicloud visibility and control with centralized policy enforcement to detect anomalous interactions and suspicious automation targeting infrastructure components
  • • Deploy cloud native security fabric (CNSF) with real-time inspection and distributed policy enforcement to provide autonomous protection against multi-stage exploit chains

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image