Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.
Quick answers
What is CVE-2026-65660?
Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.
How severe is CVE-2026-65660?
critical, CVSS 8.8
Is CVE-2026-65660 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-65660 be mitigated?
Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.
CVSS
8.8
Vendor
Microsoft
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Microsoft SharePoint, MikroTik RouterOS
Mitigation
Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.
A SharePoint Server vulnerability initially classified as a spoofing flaw with a CVSS score of 6.5 has been re-evaluated to enable authenticated remote code execution. Disclosed on September 22, 2026, the flaw affects SharePoint Server 2016, 2019, and Subscription Edition. Security researcher Dinh Ho Anh Khoa of Viettel Cyber Security published detailed technical analysis revealing that attackers with valid credentials can execute arbitrary code on affected systems. Microsoft has released patches; organizations are urged to apply updates immediately.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws impacting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The inclusion is based on evidence of active exploitation in the wild. Organizations using these products are urged to apply vendor patches immediately to reduce risk.