Code Defence Cyber security

CISA adds Microsoft SharePoint RCE CVE-2026-65660 and MikroTik RouterOS flaw CVE-2026-67279 to KEV catalog

Federal cybersecurity authorities have updated the Known Exploited Vulnerabilities catalog to order immediate remediation for two critical enterprise vulnerabilities actively weaponized in wild intrusion campaigns. Threat actors leverage network code injection and state-machine bypass errors to execute arbitrary operating system commands and hijack edge gateways.

The additions cover Microsoft Office SharePoint network code injection flaw CVE-2026-65660 alongside MikroTik RouterOS behavioral workflow flaw CVE-2026-67279. Confirmed threat telemetry shows adversaries actively exploiting SharePoint to obtain unauthenticated remote code execution across enterprise intranet servers. On edge routing hardware, adversaries chain CVE-2026-67279 with argument injection bug CVE-2026-86060 under the MikroTrick exploit vector, obtaining full administrative console access without valid credentials. Under Binding Operational Directive 26-04, federal civilian executive branch agencies face a mandatory September 28 compliance deadline.

Subverting central collaboration servers and edge routing hardware undermines enterprise document isolation and network boundary controls. Because SharePoint servers manage sensitive corporate document repositories and Active Directory credentials, an unmonitored code execution exploit permits threat actors to exfiltrate enterprise files and execute lateral movement sweeps.

– Apply official security maintenance updates released by Microsoft across all SharePoint Server installations immediately.

– Force immediate RouterOS software upgrades to patched maintenance builds published by MikroTik across edge routing hardware.

– Inspect SharePoint application logs for anomalous process creation trees or unverified remote execution requests.

– Execute system device-mode verification commands on RouterOS appliances to detect unauthorized device status changes.

Enterprise collaboration and edge network defense demand rapid security patch execution and continuous interface auditing to ensure core servers remain insulated from active wild exploitation. #CodeDefence #Microsoft #SharePoint #MikroTik #RouterOS #CISA #KEV #RCE #AppSec
/

Scroll to Top