← Back to blog

Active Exploitation of SharePoint and MikroTik Flaws Raises Alarm

CISA adds critical SharePoint RCE and MikroTik RouterOS flaws to KEV catalog due to active exploitation. Organizations are urged to patch immediately to avoid compromise.

TL;DR

  • CISA adds two actively exploited flaws to its KEV catalog: CVE-2026-65660 (SharePoint) and a MikroTik RouterOS vulnerability.
  • CVE-2026-65660 is a code injection flaw in Microsoft SharePoint with a CVSS score of 8.8.
  • Both vulnerabilities are being actively exploited in the wild, increasing risk for unpatched systems.
  • Organizations using affected versions should prioritize immediate remediation.
  • Threat actors are increasingly targeting enterprise collaboration and networking platforms.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog with two high-risk flaws—one affecting Microsoft SharePoint and another impacting MikroTik RouterOS. These vulnerabilities are not just theoretical risks; they are currently being exploited by threat actors in real-world attacks.

Organizations leveraging these technologies must act swiftly to mitigate potential breaches. The addition to CISA’s KEV list underscores the urgency, as federal agencies are required to remediate these issues within strict deadlines. Below, we break down what these vulnerabilities mean for enterprise security teams and how to respond effectively.

Microsoft SharePoint Code Injection Flaw

  • CVE-2026-65660 is a remote code execution (RCE) vulnerability in Microsoft SharePoint with a CVSS score of 8.8.
  • The flaw allows attackers to inject malicious code into vulnerable SharePoint instances without authentication.
  • It has been observed in targeted attacks against enterprise environments hosting legacy or unpatched SharePoint servers.
  • Microsoft has released patches, but many organizations remain exposed due to delayed update cycles.

MikroTik RouterOS Under Attack

  • A critical vulnerability in MikroTik's RouterOS—used widely in enterprise and ISP-grade networking equipment—is also under active exploitation.
  • While specific technical details are limited, CISA’s inclusion indicates significant risk to network infrastructure.
  • Attackers are leveraging the flaw to gain unauthorized access and potentially pivot into internal networks.
  • Organizations using MikroTik devices should review vendor advisories and apply firmware updates immediately.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.