CISA Sounds the Alarm: Two Flaws Now Under Active Attack

·
Listen to this article~4 min
CISA Sounds the Alarm: Two Flaws Now Under Active Attack

CISA just added two actively exploited flaws to its KEV catalog: a SharePoint code injection bug (CVSS 8.8) and a MikroTik RouterOS issue. Here's what you need to know and do now.

### Wait, CISA Just Flagged Two More Flaws — And Attackers Are Already Using Them You know that feeling when you see a security alert and think, "Oh great, another one"? Yeah, me too. But this one deserves a closer look. On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Translation: bad actors are already using these in the wild. No hypotheticals here. The two culprits? A code injection flaw in Microsoft SharePoint and an unspecified issue in MikroTik RouterOS. Let's break down what we know so far. ### The SharePoint Problem: CVE-2026-65660 First up, CVE-2026-65660. It's a code injection vulnerability in Microsoft Office SharePoint, and it carries a CVSS score of 8.8. That's high. Not "drop everything and panic" high, but definitely "patch this yesterday" high. Here's the thing about code injection bugs: they let an attacker run their own code on your server. That's about as bad as it gets for a collaboration platform like SharePoint, where sensitive documents and internal communications live. If someone slips through, they could potentially move laterally across your network. > "The only secure system is one that's powered off, unplugged, and locked in a room with no network — and even then, I have my doubts." — a sentiment every sysadmin knows too well. ### MikroTik RouterOS: The Quiet Threat The second flaw targets MikroTik RouterOS. CISA didn't spill all the details yet, but the fact that it's in the KEV catalog means there's confirmed exploitation. MikroTik routers are popular in small businesses and branch offices because they're affordable and packed with features. That same popularity makes them a juicy target. If you're running RouterOS, don't wait for a full advisory. Check for updates now. Seriously, close this tab and go look. ### What Should You Actually Do? - **Patch immediately.** Microsoft and MikroTik have likely released fixes. Apply them. No excuses. - **Check your logs.** Look for unusual activity around SharePoint and your router's admin interface. - **Segment your network.** Don't let a compromised router become a red carpet to your entire infrastructure. - **Limit exposure.** If your SharePoint or router admin panel is accessible from the public internet, lock it down. ### Why This Matters More Than You Think We get numb to vulnerability announcements. I know I do. But when CISA adds something to the KEV catalog, it's not theoretical. Real attackers are using these flaws right now, likely against organizations that thought they had more time. So take the 10 minutes. Patch. Verify. Breathe. Your future self will thank you. And if you're using an antidetect browser for your own security research or scraping projects, remember: the same vigilance applies. Keep your tools updated, isolate your environments, and never assume you're too small to be a target.