Skip to content

Security4 publishers2 min readPublished

Exploited WSO2 and Magento flaws draw a September 27 federal patch deadline

CISA set a September 27, 2026 federal deadline for exploited flaws in WSO2 and Adobe Commerce. According to The Hacker News, the WSO2 bug leads to code execution on API gateways, and the Magento bug lets an attacker take over customer sessions without logging in.

The Watch · Security desk

Illustration accompanying Exploited WSO2 and Magento flaws draw a September 27 federal patch deadline

What happened

  • Microsoft first described CVE-2026-65660 as a SharePoint Server spoofing flaw, then updated its advisory to say it can be abused for remote code execution.
  • CISA added the SharePoint flaw and MikroTik RouterOS bug CVE-2026-67279 to its Known Exploited Vulnerabilities catalog on Friday, citing evidence of active exploitation.
  • Security Affairs reports that CISA has ordered federal agencies to fix both flaws by September 28, 2026.
  • Security Affairs lists SharePoint Server 2016, SharePoint Server 2019 and Subscription Edition as affected by CVE-2026-65660.
  • CERT Polska says the MikroTrick chain, pairing CVE-2026-67279 with login flaw CVE-2026-86060, gives full admin control of internet-exposed routers without a password.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Teams that deferred CVE-2026-65660 as a spoofing fix now have to move it ahead of SharePoint and server work they had ranked higher.
  • exposure Any low-privileged account on an unpatched SharePoint farm, including one taken by phishing, is now enough to run code on the server.
  • constraint With no start date from Microsoft, responders patching now have no vendor date to bound how far back to hunt for intrusions that came before the fix.
  • contradiction Security Affairs cites BOD 22-01 while CISA's own alert cites BOD 26-04, whose public-exposure test could leave an internal-only SharePoint farm lower on an agency's list.

The revised entry scores 8.8 on CVSS and describes a code injection flaw that lets an authorized attacker run code over the network, according to The Hacker News [1]. Microsoft's advisory now puts exploitation on the record. "As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the company wrote [3].

The gate is a login. Security Affairs describes the attacker as authenticated and low-privileged [5]. That rules out scanning from the open internet with no account in hand.

Microsoft has not disclosed who is behind the attacks, when they started, how many organizations were targeted or breached, or what the attackers did once inside, The Hacker News reported [6]. The one date on the record is 9/25/2026, the point by which Microsoft had evidence [3].

CISA's alert ties the listing to Binding Operational Directive 26-04. The directive tells federal civilian agencies to move fast on catalog entries affecting publicly exposed assets that grant total control after exploitation, and to defer lower-risk fixes [7]. It also sets expectations for when agencies must check whether attackers compromised a system before the patch went on [8]. A patch applied after an intrusion does not remove the intruder. The directive binds only federal civilian agencies, and CISA encourages all other organizations to prioritize catalog entries [11].

The RouterOS entry scores lower and asks less of an attacker. CVE-2026-67279 rates 6.9 and lets an unauthenticated client open a session channel and send an exec request [12]. Bishop Fox reproduced the full administrative takeover on vulnerable RouterOS 7.x builds [18]. "The first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login. The second causes the login process to treat data from that connection as a trusted administrative identity," security researcher Emilio Gallegos said in Bishop Fox's analysis [19].

The RouterOS attacks predate both catalog entries. CERT Polska dates successful attacks on internet-exposed devices to at least September 2, 2026, according to Security Affairs [15]. CISA added the login flaw, CVE-2026-86060, on September 11 [16], at least nine days after those attacks began [17].

What to watch

  • A Microsoft advisory update giving a start date, an actor, or a victim count for CVE-2026-65660 attacks.
  • CISA's catalog entry confirming which directive and due date govern the SharePoint listing, given the BOD 26-04 and BOD 22-01 split between sources.
  • Public exploit code for CVE-2026-65660 appearing, widening use beyond the attackers Microsoft observed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories