A SharePoint code injection bug that Microsoft first described as a spoofing issue is now a confirmed attack surface, and federal agencies have until September 28 to close it. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 25 after Microsoft said it held reliable evidence of exploitation.
CVE-2026-65660 scores 8.8 and lets an authenticated attacker with low-level access run code over the network without user interaction. Microsoft patched it in the August 2026 Patch Tuesday batch, roughly six weeks before researchers published technical details and attackers moved.
The same KEV update swept in CVE-2026-67279, a MikroTik RouterOS flaw that lets an unauthenticated client open a session channel and send an exec request. Polish authorities say it was chained with an argument injection bug, CVE-2026-86060, in an exploit chain called MikroTrick that gave attackers full administrative control of exposed routers without a password.
Why on-premises SharePoint matters in healthcare
Health systems remain among the heaviest users of on-premises SharePoint, where intranet sites, policy libraries and departmental document stores often share a farm with clinical and financial records. An authenticated foothold inside that farm is a quiet route to PHI, and the three-week remediation window tells healthcare defenders the flaws are being worked in the wild right now.
Patch the SharePoint farm and RouterOS devices, restrict internet-facing SharePoint to known address ranges, and review authentication logs for low-privilege accounts that suddenly started executing code or spawning unusual processes.