SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS, noting that they are currently being exploited in the wild. The first vulnerability, CVE-2026-65660, has a CVSS score of 8.8 and allows for code injection in Microsoft Office SharePoint. This vulnerability poses a significant risk as it can enable attackers to execute arbitrary code on affected systems. The second vulnerability relates to MikroTik RouterOS, although specific details about it were not disclosed in the article. Organizations using these platforms should prioritize patching and securing their systems to mitigate potential attacks. The active exploitation of these vulnerabilities underscores the importance of timely updates and vigilance in cybersecurity practices.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Microsoft SharePoint, MikroTik RouterOS
- Action Required: Organizations should apply the latest security updates for Microsoft SharePoint and MikroTik RouterOS.
- Timeline: Newly disclosed
Original Article Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
Impact
Microsoft SharePoint, MikroTik RouterOS
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply the latest security updates for Microsoft SharePoint and MikroTik RouterOS. Regularly review and enhance security configurations to prevent exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Microsoft, Vulnerability, and 1 more.