These Two Flaws Are Being Exploited Right Now — Here's What You Need to Know
Michael Miller ·
Listen to this article~4 min
CISA just added two actively exploited flaws to its KEV catalog — one in SharePoint, one in MikroTik RouterOS. Here's what's happening and what you need to do.
### The Alerts You Probably Missed This Week
CISA doesn't add things to its Known Exploited Vulnerabilities catalog just to fill space. When something lands there, it means attackers are already using it in the real world. And this past Friday, two flaws made that list — one in Microsoft SharePoint and another in MikroTik RouterOS.
That's not a drill. If you're running either of these in your stack, you'll want to pay attention.
### The SharePoint Problem: CVE-2026-65660
Let's start with the big one. CVE-2026-65660 carries a CVSS score of 8.8, which puts it firmly in "serious business" territory. It's a code injection vulnerability in Microsoft Office SharePoint.
What does that mean in plain English? An attacker could potentially slip malicious code into your SharePoint environment and have it execute. No fancy tricks required — just a vulnerability that's already being probed.
Here's the thing about SharePoint: it's everywhere. Enterprises love it. Government agencies rely on it. And that's exactly why attackers love it too. One compromised SharePoint instance can open doors to documents, credentials, and internal communications.
> "The gap between disclosure and exploitation keeps shrinking. If you're waiting for a patch cycle to address critical flaws, you're already behind."
### MikroTik RouterOS: The Other Half of the Story
While the SharePoint flaw is grabbing headlines, the MikroTik RouterOS vulnerability is just as concerning. RouterOS powers a massive number of network devices — especially in small to mid-sized businesses and ISPs.
When a router gets compromised, it's not just one machine. It's your entire network's front door swinging wide open. Traffic can be intercepted, redirected, or silently monitored without anyone noticing until it's way too late.
### Why the KEV Catalog Matters
CISA's KEV catalog isn't just a list — it's a directive. Federal agencies are required to patch listed vulnerabilities within a set timeframe. But here's the reality: private organizations should treat it the same way.
- **It means active exploitation is confirmed.** Not theoretical. Not "could happen." It's happening.
- **It means the clock is ticking.** Every hour without a patch is an hour attackers have an advantage.
- **It means you need visibility.** You can't patch what you don't know you're running.
### What You Should Do Right Now
First, check if you're running vulnerable versions of SharePoint or RouterOS. If you are, patch immediately. Don't schedule it for next sprint. Don't wait for the change management window. Do it now.
Second, audit your exposure. Are these systems internet-facing? If they don't need to be, pull them behind a firewall. Reduce your attack surface before attackers do it for you.
Third, assume you might already be compromised. Check logs. Look for unusual activity. The earlier you catch something, the less damage it does.
### The Bigger Picture
This isn't just about two CVEs. It's about a pattern. Attackers are getting faster at weaponizing vulnerabilities, and defenders are getting slower at patching them. That gap is where breaches live.
If you're managing infrastructure — whether it's SharePoint, routers, or anything else — the lesson here is simple: speed matters. Visibility matters. And assuming you're not a target? That's the most dangerous assumption of all.