On 25 September the catalogue of actively exploited vulnerabilities gained CVE-2026-87902 in the WordPress core, CVE-2026-65660 in SharePoint and CVE-2026-67279 in MikroTik's RouterOS. MikroTik comes with a catch: the versions that fix it carry an incomplete fix for another of the holes.
- The WordPress hole was fixed in 7.1.2 on 22 September; by 25 September CISA already has confirmed attacks.
- CVE-2026-65660 in SharePoint is code injection that lets an authorised attacker execute code over the network, with CVSS 8.8.
- For RouterOS 7.x, per CERT Polska, the full fix for another of the holes is in 7.23.6 and 7.24.3, because 7.23.4 and 7.24.2 contain it incomplete.
Three days. That is how long it took from the WordPress patch to confirmed attacks against it.
This is the new pace, and we are not seeing it for the first time. With MikroTik, CERT Polska itself writes that comparing the patched versions with the old ones let people reconstruct some of the fixed bugs. Whoever updates once a week is already late.
MikroTik needs one more step
If you updated your routers right after MikroTik's bulletin of 3 September, you are probably on 7.23.4 or 7.24.2. That closes the hole in the catalogue, but not everything. On the 7.x branch you go to 7.23.6 or 7.24.3, depending on which branch you are on.
Then you do what both MikroTik and CERT Polska advise: check for unknown users, scripts and scheduler tasks. If the router is flagged as compromised, assume it has been taken over, save the logs and reset it.
WordPress to 7.1.2, SharePoint with the fix from Microsoft's bulletin, RouterOS 7.x to 7.23.6 or 7.24.3. Three lines, three updates.