Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure25 September 2026, Friday

CISA adds to its exploitation list on 25 September a SharePoint flaw Microsoft first published as 'spoofing' at 6.5, and a MikroTik SSH flaw

On 25 September CISA added 3 flaws to its Known Exploited Vulnerabilities (KEV) catalogue: SharePoint code injection CVE-2026-65660, MikroTik RouterOS SSH flaw CVE-2026-67279 and WordPress Core remote file inclusion flaw CVE-2026-87902. The SharePoint flaw was announced on 11 August as a spoofing flaw scored 6.5; its NVD score is 8.8.

Location: WASHINGTON

According to 2 separate CISA alerts dated 25 September, the catalogue was expanded on evidence of exploitation with the SharePoint (CVE-2026-65660), MikroTik RouterOS (CVE-2026-67279) and WordPress Core (CVE-2026-87902) flaws. According to The Hacker News, Microsoft published the flaw in its 11 August 2026 update as a spoofing flaw with a CVSS score of 6.5, while NVD scores the same bug at 8.8 as authenticated remote code execution; technical details were published on 22 September. According to a 25 September SecurityOnline report, threat analysis firm Previdian observed attack attempts in which the flaw was chained with a separate anonymous access bug and which carried encrypted .NET loaders. Affected versions are SharePoint Server 2013, 2016, 2019 and Subscription Edition; patches are included in the August 2026 cumulative updates. The move from vendor classification to in-the-wild exploitation took around 6 weeks.

On the MikroTik side, CERT Polska published 6 flaws in RouterOS on 5 September; CVE-2026-67279 allows commands to be executed in an SSH session without any authentication being attempted and was fixed in versions 7.24.2, 7.23.4 and 6.49.21. According to eSecurity Planet, attacks began on 2 September, 1 day before the patches; indicators of attack include an unexpectedly created privileged user named ops. According to The Hacker News, CISA had added the other 2 links in the same chain, CVE-2026-67277 scored 8.8 and CVE-2026-86060 scored 9.2, to the list on 12 September; thus 3 of the 6 flaws disclosed by CERT Polska are on the exploitation list. The binding patch deadline for federal agencies in this round could not be verified as it does not appear in the CISA alert; the attacks have not been attributed to a specific group.

Talay assessment

Bottom line

The 25 September list shows how a vendor's low-score classification of a flaw can delay defenders' prioritisation: the SharePoint bug was used in chained attacks around 6 weeks after it was announced as a 6.5-scored spoofing flaw. On the MikroTik side, 3 of 6 flaws entering the exploitation list indicates that attackers continue to target unpatched routers.

Likely effects

  • Corporate infrastructureNegativeWeeks

    Organisations running on-premises SharePoint Server 2013, 2016, 2019 and Subscription Edition remain exposed to chained remote code execution if they have not applied the August 2026 cumulative update.

  • Network devicesNegativeWeeks

    With 3 links of the MikroTik chain on the list, routers on versions before 7.24.2, 7.23.4 and 6.49.21 need to be scanned for indicators such as a privileged account named ops.

  • Institutions in TürkiyeUncertainWeeks

    Although KEV binds federal agencies, for public and private institutions in Türkiye using on-premises SharePoint or MikroTik, the 25 September list sets the patch priority for the same 3 flaws.

Possibilities, ranked

  1. 1
    Targeted exploitation continues55%

    The SharePoint chain and MikroTik flaws continue to be used against a limited number of targets, and no large-scale mass attack is reported.

    Watch: New compromise counts from Previdian and CERT Polska

  2. 2
    Mass scanning and ransomware30%

    Owing to public exploit code, the SharePoint flaw is used at scale in ransomware or data theft campaigns.

    Watch: Additional ransomware-linked warning from CISA or Microsoft

  3. 3
    State-backed group attribution15%

    One of the security firms links the attacks to a state-backed group and a joint agency advisory is issued.

    Watch: Joint cybersecurity advisory and group name

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Flaws added to KEV on 25 Sep▼ 3
  • SharePoint flaw score▼ 6.5→8.8
  • MikroTik chain flaws in KEV▼ 3 of 6

Sources

  1. CISA — CISA adds two known exploited vulnerabilities to catalog (25 September 2026)
  2. CISA — CISA adds one known exploited vulnerability to catalog (25 September 2026)
  3. SecurityOnline — Details of the exploited SharePoint RCE vulnerability
  4. The Hacker News — SharePoint flaw Microsoft called spoofing enables RCE
  5. CERT Polska — Vulnerabilities in MikroTik RouterOS software
  6. eSecurity Planet — MikroTik RouterOS flaws exploited via SSH
  7. The Hacker News — CISA adds 5 actively exploited vulnerabilities to KEV (12 September)