Weekly review

ThreatNoir Weekend Brief — September 27

2026-09-27Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 27, 2026

The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities enter active exploitation phases. Federal agencies face urgent patching deadlines while threat actors leverage sophisticated techniques to circumvent defensive measures across enterprise infrastructure.

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, signaling that this Microsoft SharePoint vulnerability is now subject to active exploitation in the wild. Federal agencies have been given a patching deadline of September 28, leaving minimal time for remediation efforts. The vulnerability carries significant risk to organizations relying on SharePoint infrastructure for document management and collaboration. Source: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Security researchers at watchTowr disclosed two previously unknown zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances that enable remote code execution. These flaws are currently being actively exploited in production environments, yet Citrix has neither confirmed the vulnerabilities nor released patches. The severity of the situation has prompted some system administrators to take affected appliances offline entirely rather than wait for vendor remediation. Source: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks

The threat group ShinyHunters has resumed attacks against Oracle PeopleSoft systems by exploiting CVE-2026-35273 with a novel evasion technique. The attackers employ URL encoding to circumvent Web Application Firewall rules, allowing them to deploy web shells and establish persistence through the SIDEEYE backdoor. This campaign demonstrates how threat actors continue to refine attack methodologies to overcome defensive technologies deployed by enterprise organizations. Source: ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

CISA expanded its Known Exploited Vulnerabilities catalog on Friday to include multiple critical flaws demonstrating active exploitation. Beyond CVE-2026-65660 in Microsoft SharePoint, the agency also documented CVE-2026-67279 and CVE-2026-86060 affecting MikroTik RouterOS. The SharePoint vulnerability carries a CVSS score of 8.8 and represents a code injection flaw with significant potential for system compromise. These additions to the KEV catalog reflect the urgent threat landscape facing infrastructure operators worldwide. Source: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The convergence of multiple actively exploited vulnerabilities across critical infrastructure components underscores the importance of rapid patch deployment and continuous vulnerability monitoring. Organizations should prioritize remediation efforts for all documented flaws while implementing compensating controls where patches remain unavailable.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).