- Microsoft SharePoint remote code execution vulnerability
ThreatNoir Weekend Brief — September 27
Afternoon Review in IT Security — September 27, 2026
The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities enter active exploitation phases. Federal agencies face urgent patching deadlines while threat actors leverage sophisticated techniques to circumvent defensive measures across enterprise infrastructure.
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency has added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, signaling that this Microsoft SharePoint vulnerability is now subject to active exploitation in the wild. Federal agencies have been given a patching deadline of September 28, leaving minimal time for remediation efforts. The vulnerability carries significant risk to organizations relying on SharePoint infrastructure for document management and collaboration. Source: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Security researchers at watchTowr disclosed two previously unknown zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances that enable remote code execution. These flaws are currently being actively exploited in production environments, yet Citrix has neither confirmed the vulnerabilities nor released patches. The severity of the situation has prompted some system administrators to take affected appliances offline entirely rather than wait for vendor remediation. Source: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
The threat group ShinyHunters has resumed attacks against Oracle PeopleSoft systems by exploiting CVE-2026-35273 with a novel evasion technique. The attackers employ URL encoding to circumvent Web Application Firewall rules, allowing them to deploy web shells and establish persistence through the SIDEEYE backdoor. This campaign demonstrates how threat actors continue to refine attack methodologies to overcome defensive technologies deployed by enterprise organizations. Source: ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
CISA expanded its Known Exploited Vulnerabilities catalog on Friday to include multiple critical flaws demonstrating active exploitation. Beyond CVE-2026-65660 in Microsoft SharePoint, the agency also documented CVE-2026-67279 and CVE-2026-86060 affecting MikroTik RouterOS. The SharePoint vulnerability carries a CVSS score of 8.8 and represents a code injection flaw with significant potential for system compromise. These additions to the KEV catalog reflect the urgent threat landscape facing infrastructure operators worldwide. Source: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The convergence of multiple actively exploited vulnerabilities across critical infrastructure components underscores the importance of rapid patch deployment and continuous vulnerability monitoring. Organizations should prioritize remediation efforts for all documented flaws while implementing compensating controls where patches remain unavailable.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Vulnerability in Oracle PeopleSoft exploited by ShinyHunters.
- SIDEEYEBackdoor deployed by ShinyHunters.
- x.jspJSP web shell used for command execution.
- u.jspJSP web shell used for file uploads.
- Ple64.exeTrojanized Light Alloy installer delivering SIDEEYE backdoor.
- Argument injection flaw in MikroTik RouterOS login process, chained with CVE-2026-67279.
- Improper enforcement of behavioral workflow vulnerability in MikroTik RouterOS.
- Remote code execution vulnerability in Microsoft SharePoint.