Skip to content

Sam's News β€” security β€” 2026-09-27

Security

8 Microsoft SharePoint Vulnerability CVE-2026-65660 Actively Exploited

CISA added CVE-2026-65660, a Microsoft SharePoint flaw under active exploit, to its catalog with a September 28 federal patching deadline.

  • CVE-2026-65660: Microsoft SharePoint code injection, CVSS 8.8, remote code execution, active attacks as of Sept 25
  • CVE-2026-67279: MikroTik RouterOS, CVSS 6.9, unauthenticated session channel and exec request
  • CVE-2026-67279 chained with CVE-2026-86060 in exploit "MikroTrick": full unauthenticated admin control without password
  • Works on vulnerable RouterOS 7.x builds; Bishop Fox confirmed complete administrative takeover
  • Federal agencies deadline: September 28, 2026 to patch CVE-2026-65660

Sources: SecurityWeek RSS Update to: CISA adds SharePoint RCE and MikroTik RouterOS flaws to actively exploited vulnerabilities catalog

8 Two Unpatched Citrix NetScaler Zero-Day Vulnerabilities Exploited in Wild

Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances enabling remote code execution are being actively exploited in the wild, according to security firm watchTowr reported September 26. Citrix has not confirmed the flaws or published fixes, leaving operators to choose between keeping appliances online, isolating them, or powering them off.

  • Two unpatched zero-day remote code execution vulnerabilities
  • Actively exploited in the wild before any patch existed
  • Distinct from CVE-2026-19490 (patched August 19)
  • Discovered during forensic investigations; exploitation occurred pre-patch
  • Citrix patches expected early week of September 28
  • No vendor bulletin or workaround available; future patches won't show prior access

Sources: The Hacker News AI Web Searched

7.5 ShinyHunters Hackers Expanded Attacks to Oracle PeopleSoft and Google Systems

Google's Mandiant reported on September 26 that ShinyHunters (tracked as UNC6240) renewed mass-exploitation attacks against Oracle PeopleSoft, exploiting CVE-2026-35273 (CVSS 9.8) by bypassing web application firewalls. On September 22, the group defaced FBIjobs.gov using the same vulnerability and claimed it accessed FBI-managed AWS GovCloud servers, extracting 2–3 terabytes of data including home addresses and family details of current, former, and prospective agents.

  • CVE-2026-35273: critical unauthenticated RCE in PeopleSoft, CVSS 9.8
  • Initial exploitation May 27–June 9; over 100 organizations affected, ~68% universities
  • Oracle patch issued June 10
  • Renewed attacks: adapted exploit to bypass web application firewall rules
  • Affected dozens of systems across higher education, tech, healthcare, agriculture, transportation, government
  • September 22: defaced FBIjobs.gov using same vulnerability
  • Claimed 2–3 terabytes extracted; home addresses and family details of FBI personnel
  • Reuters could not independently corroborate FBI data claims

Sources: Reuters AI Web Searched, Startup Fortune AI Web Searched, The Indian Express Web Search