we_are_coded.by CODE · The world, decoded
БГ
CISA

Three days after the patch, CISA confirmed attacks on the WordPress hole, along with SharePoint and MikroTik

CISA · event date: 25 September 2026Security

On 25 September the catalogue of actively exploited vulnerabilities gained CVE-2026-87902 in the WordPress core, CVE-2026-65660 in SharePoint and CVE-2026-67279 in MikroTik's RouterOS. MikroTik comes with a catch: the versions that fix it carry an incomplete fix for another of the holes.

In short
  • The WordPress hole was fixed in 7.1.2 on 22 September; by 25 September CISA already has confirmed attacks.
  • CVE-2026-65660 in SharePoint is code injection that lets an authorised attacker execute code over the network, with CVSS 8.8.
  • For RouterOS 7.x, per CERT Polska, the full fix for another of the holes is in 7.23.6 and 7.24.3, because 7.23.4 and 7.24.2 contain it incomplete.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Three days. That is how long it took from the WordPress patch to confirmed attacks against it.

This is the new pace, and we are not seeing it for the first time. With MikroTik, CERT Polska itself writes that comparing the patched versions with the old ones let people reconstruct some of the fixed bugs. Whoever updates once a week is already late.

The facts: on 25 September 2026 CISA added three entries to its Known Exploited Vulnerabilities (KEV) catalogue, with a deadline of 28 September for US federal agencies. CVE-2026-87902 is in the WordPress core: an unauthenticated attacker can make page-template resolution include a chosen local .php file, which under certain conditions leads to code execution; the fix came out in version 7.1.2 on 22 September and was backported to the 4.7 branch. CVE-2026-65660 is code injection in Microsoft SharePoint that allows an authorised attacker to execute code over the network, rated 8.8 on CVSS; the NVD record dates from 11 August 2026. CVE-2026-67279 is in MikroTik RouterOS's SSH server, which after a client-requested rekey enters the connection protocol without any login having taken place and lets an unauthenticated client create and overwrite files; it is fixed in 6.49.21, 7.23.4 and 7.24.2. It is one of six RouterOS vulnerabilities found by CERT Polska, which on 5 September reported active attacks on a chain of two of them. According to CERT Polska, versions 7.23.4 and 7.24.2 contain an incomplete fix for another of the six, CVE-2026-67278, which is closed in 7.23.6 and 7.24.3.

MikroTik needs one more step

If you updated your routers right after MikroTik's bulletin of 3 September, you are probably on 7.23.4 or 7.24.2. That closes the hole in the catalogue, but not everything. On the 7.x branch you go to 7.23.6 or 7.24.3, depending on which branch you are on.

Then you do what both MikroTik and CERT Polska advise: check for unknown users, scripts and scheduler tasks. If the router is flagged as compromised, assume it has been taken over, save the logs and reset it.

An updated router with a stranger's user inside is only updated.

WordPress to 7.1.2, SharePoint with the fix from Microsoft's bulletin, RouterOS 7.x to 7.23.6 or 7.24.3. Three lines, three updates.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA: Known Exploited Vulnerabilities Catalog→CVE-2026-87902, WordPress Core (NVD)→CVE-2026-65660, Microsoft SharePoint (NVD)→CVE-2026-67279, MikroTik RouterOS (NVD)→WordPress.org - WordPress 7.1.2 Release, 22.09.2026→MikroTik - September 2026 vulnerability, 03.09.2026→CERT Polska - Vulnerabilities in Mikrotik RouterOS software, 05.09.2026
Original: https://wearecoded.com/en/articles/cisa-kev-wordpress-sharepoint-mikrotik.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news