CISA's Latest Alert: Two Critical Flaws Under Active Attack
Emily Davis ·
Listen to this article~4 min
CISA adds two actively exploited flaws to its KEV catalog: a critical SharePoint code injection (CVE-2026-65660) and a MikroTik RouterOS vulnerability. Here's what you need to know and do now.
You know that feeling when you wake up, check your phone, and see a security alert that makes your stomach drop? That's exactly what happened Friday when the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two serious vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. And these aren't just theoretical risks—they're being actively exploited in the wild right now.
### What Exactly Got Flagged?
CISA added two flaws, but the one grabbing headlines is **CVE-2026-65660**, a code injection vulnerability in Microsoft Office SharePoint. It carries a CVSS score of 8.8, which puts it firmly in the "high severity" category. The other flaw affects MikroTik RouterOS, a popular operating system for routers and network devices. Both are now confirmed to be under active exploitation.
If you're wondering what "code injection" actually means in plain English: an attacker can slip malicious code into your SharePoint environment and run it. That could let them steal data, move laterally across your network, or plant backdoors. Not exactly a minor oops.
### Why This Matters More Than Your Average Patch Tuesday
Here's the thing—CISA doesn't add just any vulnerability to the KEV catalog. They only list flaws that are being actively exploited. So when you see SharePoint and MikroTik RouterOS on that list, it's time to pay attention.
> "The KEV catalog is essentially a hit list for attackers," says one security researcher. "If your system is on it, you're already a target."
For IT teams in the U.S., this means two things:
- **Patch immediately.** Don't wait for your normal maintenance window. These exploits are live.
- **Check your exposure.** If you're running unpatched SharePoint or MikroTik RouterOS, assume you've been probed—or worse.
### The Bigger Picture: Why Antidetect Browsers Enter the Conversation
You might be thinking, "What do antidetect browsers have to do with router and SharePoint flaws?" Honestly, more than you'd expect. Attackers often use antidetect browsers to manage multiple compromised accounts without getting flagged. They spoof fingerprints, rotate IPs, and blend in like normal users. So while you're patching your servers, it's also worth understanding how these tools work—both to defend against them and to recognize the signs of an intrusion.
If you're in the security space, knowing the tactics is half the battle. And if you're just trying to keep your business safe, well, now you know what to look for.
### What Should You Do Right Now?
- **Apply the patches.** Microsoft and MikroTik have released fixes. Get them on your systems today.
- **Review your logs.** Look for unusual activity around SharePoint and your routers.
- **Educate your team.** Phishing and social engineering often follow these exploits.
- **Consider layered defense.** Antidetect browsers aren't just for privacy enthusiasts—they're a reminder that attackers have sophisticated tools too.
At the end of the day, security is about staying one step ahead. CISA just gave us a heads-up. The question is: will you act on it?