Microsoft SharePoint and MikroTik RouterOS Vulnerabilities Actively Exploited in the Wild
The U.S. CISA added two critical vulnerabilities, CVE-2026-65660 (RCE in Microsoft SharePoint) and CVE-2026-67279 (unauthenticated access in MikroTik RouterOS), to its KEV catalog due to active exploitation. An exploit chain named MikroTrick combines these flaws to enable full administrative control of vulnerable routers without authentication.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
*** END OF TRANSMISSION ***