# CISA Mandates Patch for SharePoint and MikroTik Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has added critical remote code execution vulnerabilities in Microsoft SharePoint (CVE-2026-65660) and MikroTik RouterOS (CVE-2026-67279 and CVE-2026-86060) to its Known Exploited Vulnerabilities catalog, requiring all federal agencies to apply security patches by September 28, 2026. These vulnerabilities allow attackers to gain administrative access without passwords, posing significant risks to government and private sector networks. This directive creates immediate demand for cybersecurity contractors specializing in vulnerability remediation, patch management, and network security monitoring to assist agencies in meeting compliance deadlines and mitigating exploitation risks.

- **Why this matters:** Federal agencies must comply with CISA's mandatory patching deadline to avoid potential breaches and operational disruptions.
- Cybersecurity firms can leverage this urgent requirement to offer services in vulnerability assessment, patch deployment, and continuous monitoring.
- Organizations supporting federal IT infrastructure should prioritize updating affected Microsoft SharePoint and MikroTik RouterOS systems to maintain security posture.
- This action underscores the importance of proactive vulnerability management and rapid response capabilities in government procurement strategies.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 26, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- CERT Polska

### Vendors
- Microsoft (software vendor)
- MikroTik (router OS vendor)
- Bishop Fox (security research firm)

### Key Quotes
> The chain crosses two trust boundaries: one flaw exposes a function meant for trusted callers, while the other lets attacker-controlled login data gain administrative treatment.
> — Emilio Gallegos, Researcher

> Microsoft said it had reliable evidence of attacks exploiting the flaw as of Sept. 25.
> — Microsoft

> The pair can give an attacker access to the administrative console without a password.
> — CERT Polska

### Sources
- [SharePoint RCE and MikroTik RouterOS flaws face active exploitation | LavX News](https://news.lavx.hu/article/sharepoint-rce-and-mikrotik-routeros-flaws-face-active-exploitation) - news.lavx.hu