CYBERSECURITYTRACKER
TRACKING
Permanent story citation

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8641

As cited

Copy frozen at (site build).

vulnerabilities

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660, a code injection vulnerability in Microsoft Office SharePoint, and a MikroTik RouterOS flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 26, 2026. Both flaws are being actively exploited in the wild.

Why it matters: SharePoint administrators and MikroTik device operators must prioritize patching these vulnerabilities immediately, as active exploitation poses direct risk to their systems and the CISA KEV listing signals widespread threat activity.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary