The Cybersecurity and Infrastructure Security Agency added a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog on September 25, 2026, and gave federal civilian agencies until September 28 to patch it. The bug, tracked as CVE-2026-65660, carries a CVSS score of 8.8 and lets an authenticated, low-privileged attacker run arbitrary code on on-premises SharePoint deployments. CISA added it alongside a second, unrelated flaw in MikroTik RouterOS, and both entries point to the same underlying story: attackers are already inside networks running this software, and the clock federal agencies have to respond is measured in days, not weeks.
The addition matters beyond the federal government. CISA’s KEV catalog functions as a de facto national patch-priority list, and security teams at banks, hospitals, and manufacturers use it to decide what gets fixed first. SharePoint Server’s history with attackers, most visibly the 2025 ToolShell campaign, gives this entry extra weight. Below is what CISA confirmed, what independent researchers found, and what it means for anyone still running SharePoint on their own hardware.
What Happened: CISA’s September 25 KEV Addition
According to reporting from Security Affairs journalist Pierluigi Paganini, CISA’s Known Exploited Vulnerabilities catalog picked up two new entries on September 25, 2026: CVE-2026-65660, a code-injection vulnerability in Microsoft SharePoint Server, and CVE-2026-67279, an SSH protocol flaw in MikroTik RouterOS. Both were added because CISA had evidence of active exploitation in the wild, the threshold the agency requires before a vulnerability lands on the list. The catalog notice itself uses language CISA repeats on nearly every KEV entry: “These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.”
The two vulnerabilities have nothing to do with each other technically. They share a catalog entry date because CISA batches KEV additions as it confirms exploitation, not because the underlying bugs are related. That distinction matters for triage: a SharePoint administrator doesn’t need to worry about RouterOS, and a network operator running MikroTik gear doesn’t need to patch SharePoint. But both organizations now face the same September 28 federal deadline if they are covered entities, and both bugs are illustrative of a pattern CISA has flagged repeatedly this year: widely deployed enterprise infrastructure software, patched months ago for a different flaw, getting hit again through a new code path.
Inside CVE-2026-65660: The SharePoint Code-Injection Flaw
CVE-2026-65660 is a code-injection vulnerability in on-premises Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary code remotely, according to Security Affairs’ reporting. Microsoft’s own advisory, published through its Security Update Guide, dates the disclosure to August 11, 2026, and Microsoft shipped a fix in that month’s security update cycle under support article KB5002905. The flaw’s CVSS vector breaks down as network-exploitable, low attack complexity, requiring low privileges, no user interaction, with high impact to confidentiality, integrity, and availability once triggered. The vulnerability is also indexed in the National Vulnerability Database under its CVE identifier.
What Makes It Exploitable
The “authenticated, low-privileged” qualifier is doing a lot of work here. It means the flaw isn’t a wide-open front door, an attacker needs some form of valid SharePoint account first, whether through stolen credentials, a phished session, or a foothold gained via another vulnerability. That’s a meaningfully different risk profile than an unauthenticated RCE, but it’s not much comfort in practice: credential theft is cheap, phishing kits are commodity tools, and any organization with SharePoint exposed to the internet or reachable from a compromised endpoint should assume the authentication bar is not a real barrier.
Affected Products
The flaw affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, meaning it is specific to on-premises deployments rather than SharePoint Online in Microsoft 365. That distinction has become the single most important variable in how exposed an organization is: cloud-hosted SharePoint tenants sit behind Microsoft’s own patching cadence and are not directly affected by this KEV entry, while self-hosted instances depend entirely on each organization’s own IT team applying the August update.
The Second Flaw: MikroTik RouterOS and the “MikroTrick” Chain
CVE-2026-67279 carries a lower CVSS score of 6.9, but the way it’s being used is arguably more alarming. Per Security Affairs, the bug is an SSH protocol flaw in MikroTik RouterOS that lets an unauthenticated attacker bypass the normal authentication flow, open a session channel, and execute commands, including creating or modifying files on the device. Poland’s national CERT, CERT Polska, confirmed the flaw is being actively exploited and found that when chained with a separate vulnerability, CVE-2026-86060, it can escalate to full administrative access without any authentication at all. Researchers have nicknamed the combined attack path “MikroTrick.”
CERT Polska traced successful attacks against internet-exposed RouterOS devices back to at least September 2, 2026, meaning the exploitation window predates CISA’s catalog addition by more than three weeks. MikroTik routers are a fixture in small ISPs, branch offices, and budget network deployments worldwide, which gives this bug a long tail: unlike SharePoint, where enterprise IT teams generally have patch management processes, RouterOS devices are frequently deployed once and left alone for years.
| Detail | CVE-2026-65660 (SharePoint) | CVE-2026-67279 (RouterOS) |
|---|---|---|
| CVSS score | 8.8 | 6.9 |
| Vulnerability type | Code injection / RCE | SSH auth bypass |
| Access needed | Authenticated, low privilege | Unauthenticated |
| Chained with | None reported | CVE-2026-86060 (“MikroTrick”) |
| Earliest observed exploitation | Not publicly dated | September 2, 2026 (CERT Polska) |
| Federal patch deadline | September 28, 2026 | September 28, 2026 |
Why CISA’s Three-Day Deadline Matters
CISA’s remediation deadlines run under Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities,” which requires Federal Civilian Executive Branch agencies to fix cataloged vulnerabilities by a due date the agency sets on a case-by-case basis. A three-day window between the September 25 catalog addition and the September 28 deadline is aggressive even by KEV standards, and it reflects how CISA calibrates urgency: the shorter the deadline, the higher the agency’s confidence that exploitation is active and spreading rather than isolated or theoretical.
This isn’t the first compressed deadline of the year. CISA gave agencies a similarly tight three-day window after adding an Arista zero-day rated CVSS 10.0 to the catalog, and it moved quickly on the F5 BIG-IP zero-day tracked as CVE-2026-94127, also rated CVSS 9.8. The pattern this year has skewed toward faster deadlines for perimeter and infrastructure software, the kind of equipment that, once compromised, gives an attacker a foothold across an entire network rather than a single machine.
BOD 22-01 only binds federal agencies directly, but CISA explicitly recommends that private-sector organizations treat the catalog the same way. In practice, most enterprise security teams already do: KEV inclusion has become the industry’s shorthand for “this is not a theoretical risk,” and vulnerability management platforms widely use catalog membership as an automatic severity escalator regardless of an organization’s regulatory obligations.
Historical Context: SharePoint’s ToolShell Precedent
This is not on-premises SharePoint’s first appearance in the KEV catalog, and that history is exactly why security teams are taking this addition seriously. In July 2025, a campaign researchers named ToolShell exploited two SharePoint Server flaws, CVE-2025-53770 (CVSS 9.8) and CVE-2025-53771 (CVSS 6.3), both of which Microsoft described as bypasses of earlier patches for CVE-2025-49704 and CVE-2025-49706. CISA added CVE-2025-53770 to the KEV catalog on July 20, 2025, the same week Microsoft rushed out emergency updates.
ToolShell’s Lessons
MITRE’s campaign documentation ties ToolShell exploitation to the ransomware actor tracked as Storm-2603, alongside the espionage-focused groups Threat Group-3390 and ZIRCONIUM, and records deployment of ransomware families including Warlock and 4L4MD4R against compromised SharePoint servers. One contemporaneous research estimate put the toll at roughly 85 servers across 29 organizations, though CISA and independent researchers were explicit that this was a floor, not a final count, since the true scope was still being assessed weeks after disclosure.
The lesson enterprises took from ToolShell was that on-premises SharePoint is a target ransomware crews actively hunt for, not an incidental casualty of broader Microsoft exploitation. CVE-2026-65660 arriving in the same product line just over a year later, on the same three supported SharePoint branches, is the reason security researchers are treating this KEV addition as a repeat pattern rather than an isolated bug.
How 2026’s KEV Additions Compare
SharePoint’s addition joins a crowded year for enterprise infrastructure software on CISA’s list. Comparing the CVSS scores across 2026’s major KEV entries shows a consistent theme: the vulnerabilities drawing the fastest deadlines are the ones sitting at the network edge or providing broad administrative reach once compromised.
| Product | CVE | CVSS | Category |
|---|---|---|---|
| Microsoft SharePoint Server | CVE-2026-65660 | 8.8 | On-prem collaboration software |
| JetBrains TeamCity | CVE-2026-63077 | 9.8 | CI/CD build server |
| Cisco ISE | CVE-2026-76460 | 10.0 | Network access control |
| F5 BIG-IP | CVE-2026-94127 | 9.8 | Application delivery controller |
| VMware vCenter | CVE-2026-59310 | 9.8 | Virtualization management |
| MikroTik RouterOS | CVE-2026-67279 | 6.9 | Network router firmware |
SharePoint’s CVSS 8.8 is actually the lowest of the enterprise-software group in that table, which underlines that CVSS score alone doesn’t determine KEV urgency. CISA’s inclusion criteria center on confirmed active exploitation, not raw severity, so a lower-scored bug that’s already being weaponized against real targets jumps the queue ahead of higher-scored flaws that remain theoretical.
Market Impact: Enterprises Still Running On-Prem SharePoint
The organizations most exposed here are the ones that, for regulatory, data-residency, or legacy-integration reasons, never migrated to SharePoint Online. That population skews toward government contractors, healthcare systems, financial institutions with strict data-sovereignty requirements, and large enterprises with deep customizations built on top of on-premises SharePoint over a decade or more. For those organizations, migrating off the platform isn’t a quick decision, which means the realistic near-term response is patching and network segmentation rather than migration.
There’s a secondary market effect worth noting: incidents like this one tend to accelerate cloud migration budgets, even when the immediate fix is a patch rather than a platform change. After ToolShell in 2025, several IT analysts reported an uptick in SharePoint Online migration inquiries specifically citing patch-management fatigue with on-premises servers. A second high-profile KEV entry on the same product line just over a year later is likely to reinforce that trend rather than reverse it, particularly among enterprises weighing renewal decisions on their SharePoint Server licensing.
Security vendors that sell vulnerability management and attack-surface-monitoring tools also stand to benefit from renewed attention on the KEV catalog. The broader trend this year, visible across the UK’s reported 43% cyber-breach rate among businesses, has been enterprises treating KEV membership as a procurement trigger, prioritizing tools that can flag catalog matches automatically across their asset inventory.
Detection and Patch Guidance for IT Teams
Administrators running on-premises SharePoint Server 2016, 2019, or Subscription Edition should confirm the August 2026 security update is installed rather than assume a general patching cadence already covered it, since cumulative update applicability varies by edition and installed baseline. Microsoft’s security update portal is the authoritative reference for the correct build number for each specific deployment. A basic first check on the server itself looks like this:
# Run on the SharePoint server to check the installed farm build version
Get-SPFarm | Select-Object BuildVersion
# Cross-reference the returned build number against Microsoft's
# Security Update Guide advisory for CVE-2026-65660 to confirm
# the August 11, 2026 fix is applied to this specific edition.
For MikroTik RouterOS devices, CERT Polska’s guidance centers on two immediate steps: disabling SSH access from the WAN interface where it isn’t strictly required, and updating to the RouterOS release that addresses CVE-2026-67279 and the chained CVE-2026-86060. Network operators managing fleets of RouterOS devices at branch offices or customer sites should treat internet-facing SSH exposure as the priority signal, since CERT Polska’s confirmed exploitation specifically targeted internet-exposed devices rather than internally isolated ones.
The Broader Pattern: 2026’s Surge in On-Prem Software KEV Entries
Zoom out from any single vendor and a pattern emerges across 2026’s KEV additions: self-hosted enterprise infrastructure, the software organizations run on their own servers rather than consume as a cloud service, has dominated the list. TeamCity, Cisco ISE, F5 BIG-IP, VMware vCenter, and now SharePoint Server all fit that description, alongside the Citrix NetScaler zero-days that drew scrutiny earlier this year. Cloud-hosted equivalents of most of these products exist and carry a fundamentally different risk profile, since the hosting provider controls and applies the patch on a timeline the customer doesn’t manage directly.
That divergence is becoming a genuine competitive factor in enterprise software purchasing. Vendors selling managed or cloud-hosted versions of traditionally on-premises tools now have a concrete talking point: KEV catalog membership skews overwhelmingly toward self-managed deployments, because attackers know patch compliance is inconsistent across thousands of independently administered servers in a way it isn’t across a single cloud provider’s fleet. That argument doesn’t eliminate the value of on-premises control for regulated industries, but it does raise the operational cost of choosing it.
Competitive Landscape: Cloud SharePoint vs. On-Premises Exposure
Microsoft’s own SharePoint Online tenants are not directly affected by CVE-2026-65660, since the flaw is specific to the on-premises server codebase. That split creates an unusual dynamic where Microsoft is simultaneously the vendor shipping the emergency fix and the beneficiary of the underlying pressure pushing customers toward its cloud product. Competing document-collaboration platforms hosted natively in the cloud, without an on-premises legacy version to maintain, don’t carry this specific exposure at all, which is likely to feature in competitive sales conversations over the next few quarters.
For MikroTik, the competitive picture is different because RouterOS doesn’t have a direct cloud-hosted equivalent, it’s embedded firmware running on physical routers. The realistic alternative for security-conscious network operators isn’t a cloud migration but a hardware and firmware vendor evaluation, weighing MikroTik’s low cost and wide adoption against enterprise-grade router vendors with more consistent patch cadences and professional support contracts.
What Happens Next: Predictions
Based on the pattern this vulnerability follows and the precedent set by ToolShell, a handful of near-term developments look likely:
- Ransomware operators will likely add CVE-2026-65660 to their initial-access toolkits within weeks rather than months, mirroring how quickly Storm-2603 moved on ToolShell in 2025.
- CISA will probably issue a follow-up advisory or update the KEV entry if exploitation broadens beyond the current, narrower authenticated-access pattern to include a chained privilege-escalation path.
- Organizations still running SharePoint Server 2016, now years past its mainstream support cutoff for new features, will face growing pressure from their own security teams to isolate or retire it rather than continue patching in place.
- MikroTik’s installed base means CVE-2026-67279 will likely persist as an active exploitation vector well after this KEV cycle closes, since unmanaged branch-office routers are patched far less consistently than enterprise servers.
- Expect CISA to continue compressing remediation deadlines for perimeter and infrastructure software throughout the rest of 2026, following the same three-day pattern set here and with the Arista and F5 entries earlier this year.
Outlets tracking the vulnerability landscape closely, including The Hacker News, have flagged the same on-premises-infrastructure pattern this KEV addition fits, reinforcing why security teams treat catalog membership as an operational trigger rather than a bureaucratic formality. For a broader look at how these disclosures fit together, see shattered.io’s security coverage.
Patch Priority Checklist
| Step | Action | Owner |
|---|---|---|
| 1 | Confirm SharePoint Server edition and current build version | SharePoint admin |
| 2 | Apply the August 11, 2026 security update if not already installed | SharePoint admin |
| 3 | Audit SharePoint account privileges to limit low-level accounts that could trigger the flaw | Identity/IAM team |
| 4 | Inventory all internet-facing MikroTik RouterOS devices | Network operations |
| 5 | Disable WAN-facing SSH on RouterOS devices where not required | Network operations |
| 6 | Update RouterOS to the release addressing CVE-2026-67279 and CVE-2026-86060 | Network operations |
| 7 | Cross-check both CVEs against CISA’s KEV catalog for deadline compliance | Security/compliance |
Frequently Asked Questions
What is CVE-2026-65660?
It’s a code-injection vulnerability in on-premises Microsoft SharePoint Server that lets an authenticated, low-privileged attacker execute arbitrary code remotely. Microsoft disclosed it and shipped a fix on August 11, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on September 25, 2026, after confirming active exploitation.
How severe is the SharePoint vulnerability?
CVE-2026-65660 carries a CVSS score of 8.8, in the high-severity range. It requires authentication, so it’s not as immediately dangerous as an unauthenticated remote-code-execution flaw, but its inclusion on CISA’s KEV catalog confirms attackers are already exploiting it in real environments.
What is CISA’s KEV catalog and why does it matter?
The Known Exploited Vulnerabilities catalog is CISA’s list of software flaws with confirmed real-world exploitation. Under Binding Operational Directive 22-01, federal civilian agencies must patch cataloged vulnerabilities by a set deadline. Private-sector organizations aren’t legally bound by it, but most security teams treat KEV membership as a strong signal to prioritize a fix.
When must federal agencies patch the SharePoint flaw?
CISA set a remediation deadline of September 28, 2026, for CVE-2026-65660, just three days after adding it to the catalog on September 25.
Is my organization at risk if we use SharePoint Online instead of on-premises servers?
CVE-2026-65660 affects on-premises SharePoint Server 2016, 2019, and Subscription Edition. SharePoint Online tenants hosted in Microsoft 365 are not directly affected by this specific flaw.
What is the “MikroTrick” chain?
It’s the nickname researchers gave to combining CVE-2026-67279, an SSH authentication bypass in MikroTik RouterOS, with a second flaw, CVE-2026-86060, to gain full administrative access to a device without any authentication at all. CERT Polska confirmed active exploitation of this chain against internet-exposed RouterOS devices dating back to at least September 2, 2026.
How does this compare to the 2025 ToolShell SharePoint attacks?
ToolShell exploited two different SharePoint flaws, CVE-2025-53770 and CVE-2025-53771, starting in July 2025, and was tied by MITRE’s campaign tracking to the ransomware actor Storm-2603 and ransomware families including Warlock. CVE-2026-65660 is a separate, newer vulnerability in the same product line, and its KEV addition has renewed comparisons to that earlier campaign given SharePoint Server’s repeated targeting.
What should IT teams do right now?
Confirm the August 2026 SharePoint security update is applied, audit account privileges on SharePoint servers, inventory any internet-facing MikroTik RouterOS devices, disable unnecessary WAN-facing SSH access, and update RouterOS firmware to the version that addresses both CVE-2026-67279 and CVE-2026-86060.




