Search
Find merged stories by title or summary.
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-65660 (CVSS score of 8.8) Microsoft SharePoint Code Injection Vulnerability • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary code remotely. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition. The second flaw added to the catalog, tracked as CVE-2026-67279 (CVSS score of 6.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2026-67279 - Confirmed Exploitation
CVE-2026-67279 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-25 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-25 Asserted: 2026-09-25
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
MikroTik SSH Rekeying and Username Flaws Chain Into Unauthenticated RouterOS Admin Access
Attackers can combine two MikroTik RouterOS vulnerabilities to gain administrator-level access to exposed routers without a password. Security researchers at Bishop Fox reproduced the attack chain and found artifacts on real devices that suggest attackers exploited the flaws before public fixes became available. The issue is especially serious because routers handle traffic between internal networks and the internet. A compromised MikroTik device could allow attackers to monitor traffic, steal credentials, maintain access, or move deeper into connected networks. CERT Polska disclosed six actively exploited RouterOS flaws on September 5, 2026. Two of them, tracked as CVE-2026-67279 and CVE-2026-86060, can be chained in an attack known as “MikroTrick.” MikroTik released fixes for all six issues.
AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
Number: AL26-020 Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1 .
[Previdian] CVE-2026-67277 - Confirmed Exploitation
CVE-2026-67277 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-10 19:50 UTC Evidence Sources: 1 First Seen: 2026-09-10 Asserted: 2026-09-10
[Previdian] CVE-2026-67276 - Confirmed Exploitation
CVE-2026-67276 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-10 16:25 UTC Evidence Sources: 1 First Seen: 2026-09-10 Asserted: 2026-09-10
NVD-CVE-2026-67279 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-67279 National Institute of Standards and Technology (.gov)
NVD-CVE-2026-67276 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-67276 National Institute of Standards and Technology (.gov)
CVE-2026-67277 - Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
CVE ID : CVE-2026-67277 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 8.8 • HIGH
CVE-2026-67278 - TLS server impersonation possible in Mikrotik RouterOS
CVE ID : CVE-2026-67278 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : MikroTik RouterOS accepts malformed RSA/PKCS#1 v1. 5 signatures during X. 509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 6.3 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67279 - SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE ID : CVE-2026-67279 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 6.9 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67276 - SSH user impersonation possible in Mikrotik RouterOS
CVE ID : CVE-2026-67276 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 9.2 • CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
• 42 Critical • 355 Important • 1 Moderate • 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.
CVE-2026-6727 - National Institute of Standards and Technology (.gov)
CVE-2026-6727 National Institute of Standards and Technology (.gov)
VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2. 0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2. 0 attestations. TCGVRT010 and TCGVRT0011: Description Trusted Platform Module (TPM) technology provides hardware-backed cryptographic services for modern computing platforms.
You've reached the end of current stories for this search.
