The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws impacting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, acting on concrete evidence that both vulnerabilities are actively being weaponized in the wild. The inclusion of these vulnerabilities underscores the ongoing challenges organizations face in defending enterprise collaboration platforms and internet-facing network infrastructure against sophisticated, multi-stage attacks. Federal agencies and private enterprises alike are being urged to prioritize remediation as threat actors increasingly leverage unpatched services to establish initial footholds and execute unauthorized commands. Read Also: Why Isolated Security Testing Fails: The Rise of Autonomous Attack Chaining in Enterprise Defense OnePlus Faces Scrutiny After Security Researcher Publicly Discloses Unpatched Root-Level Flaws in OxygenOS Evolving Threat Landscape for Microsoft SharePoint The first of the newly cataloged flaws, tracked as CVE-2026-65660, was originally characterized by Microsoft as a routine spoofing vulnerability affecting SharePoint Server. However, subsequent analysis and updated advisories from the tech giant reveal a far more dangerous reality: the flaw can be abused by malicious actors to achieve remote code execution (RCE) on targeted servers. According to Microsoft, reliable evidence confirms that real-world threat actors have actively exploited this vulnerability in targeted attacks. While the exact scope, scale, and specific methodology of these campaigns remain under investigation, the potential for remote code execution makes the flaw a severe risk for any organization hosting internal or external SharePoint environments. Microsoft has not yet publicly disclosed comprehensive attribution details, such as the identities of the threat groups behind the exploitation, the precise timeline of when attacks commenced, the exact number of targeted organizations, or the specific post-exploitation actions taken by intruders once administrative access was achieved. Despite this lack of granular forensic visibility, the active exploitation status confirmed by both Microsoft and CISA signals an urgent requirement for administrators to apply the latest security updates immediately to mitigate potential compromise. The "MikroTrick" Exploit Chain and MikroTik RouterOS The second addition to CISA’s catalog involves a high-severity exploit chain known as "MikroTrick," which targets internet-exposed MikroTik RouterOS devices running vulnerable 7.x builds. This sophisticated attack mechanism combines two distinct security failures at different trust boundaries within the software architecture to achieve full administrative control without requiring user credentials. The exploit chain centers around CVE-2026-67279, which has been successfully chained alongside CVE-2026-86060—an argument injection vulnerability residing within the RouterOS login process. Insights shared by CERT Polska highlight that the combination of these two weaknesses results in complete, unauthenticated access to the router’s administrative console. Specifically, CVE-2026-67279 permits an unauthenticated client to successfully establish a session channel, bypassing standard authentication gates. Following this initial connection, CVE-2026-86060 allows the attacker to supply login parameters featuring an arbitrary, attacker-controlled policy mask. Independent security analysis conducted by Bishop Fox successfully replicated this complete administrative takeover on vulnerable RouterOS 7.x builds, confirming the severity of the flaw. Security researcher Emilio Gallegos noted that MikroTrick effectively exposes a fundamental design risk in privileged software, wherein features originally intended solely for trusted local callers inadvertently transform into remote attack surfaces whenever an upstream software component loses track of the current authentication state. In this scenario, the first vulnerability allows an unauthenticated network connection to reach operational functionality that RouterOS should normally expose only after a successful login. The second vulnerability then compels the login process to treat untrusted data originating from that connection as a verified administrative identity. Broader Implications and Remediation Deadlines The expansion of CISA’s KEV catalog reflects a broader trend of adversaries rapidly weaponizing vulnerabilities that bridge trust boundaries or grant remote code execution capabilities. Because CVE-2026-86060 was previously added to the KEV catalog by CISA on September 11, 2026, network administrators and federal entities have already been tracking related exposures in MikroTik infrastructure. Federal Civilian Executive Branch (FCEB) agencies face strict compliance mandates to apply necessary patches and mitigations within designated timeframes, while private sector organizations are strongly advised to align their patch management schedules with these federal benchmarks. Given the severity of remote code execution in enterprise document management platforms like SharePoint and the complete loss of control associated with the MikroTrick chain in network routing equipment, security teams must treat both vulnerabilities as high-priority remediation items to prevent widespread network compromise. Post navigation Critical Security Flaw Discovered in Elementor Plugin Threatens Over Two Million WordPress Sites Lunex Malware-as-a-Service Platform Unmasked as the Engine Behind Psychedelic Stealer Attacks in Ukraine