Authenticated SharePoint RCE, vendor-confirmed observed attacks, federal clock ending today. That is the Monday KEV follow-on — not a second breaking Citrix lead.
Primary: MSRC advisory for CVE-2026-65660 (Microsoft Office SharePoint). Classed as code injection enabling an authorized attacker to execute code over a network. CVSS cited in secondary coverage: 8.8. Microsoft initially framed it as medium-severity spoofing (per Viettel / SecurityWeek); later revised to high-severity RCE. On its own it is a type-check bypass that yields code execution for an authenticated attacker; reaching unauthenticated RCE requires chaining a separate auth-bypass; Microsoft has not published such a chain.
Exploitation timeline (secondary, consistent across SecurityWeek / The Hacker News): roughly six weeks after the August patch, and days after Viettel Security (who reported the bug to Microsoft) published technical details. Previdian (formerly KEVIntel) reported exploitation attempts on September 24; on September 25 it saw attempts to create a webshell backdoor. THN citing Previdian: 16 exploitation attempts against its sensors on Sep 24 (UK / Israel-sourced IPs in that write-up) — that is a sensor attempt count, not a victim census. Who is behind it, how many orgs were hit, and what attackers did post-access beyond webshell attempts: Undisclosed by Microsoft.
CISA Sep 25 alert: two new KEV rows — CVE-2026-65660 (Microsoft SharePoint Code Injection) and CVE-2026-67279 (MikroTik RouterOS Improper Enforcement of Behavioral Workflow). BOD 26-04 still governs FCEB remediation of KEV entries on publicly exposed assets that grant total control post-exploitation; secondary reporting puts the SharePoint federal deadline at September 28.
Optional same-day pair — MikroTrick: CERT Polska technical analysis explains CVE-2026-67279 (SSH rekey state machine lets an unauthenticated client open a session channel) chained with CVE-2026-86060 (argument injection in RouterOS login → attacker-controlled policy mask) for full unauthenticated admin on internet-exposed susceptible RouterOS. CISA had already KEV’d 86060 earlier (Sep 11 per THN); 67279 joined on Sep 25. Primary for the chain: CERT Polska. This brief covers the patch and advisory only, not exploit steps.
POV: If you still run on-prem SharePoint that missed August’s build, today is the FCEB clock and the board clock. Hunt for webshells before you overwrite evidence. Pair MikroTik internet-exposed RouterOS with CERT Polska’s MikroTrick guidance. Sources: MSRC + CISA Sep 25; the Sep 24–25 attempt / webshell window is per SecurityWeek / THN / Previdian. Victim and actor counts stay Undisclosed.
