SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Summary

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog: a code injection flaw in Microsoft SharePoint and a separate vulnerability in MikroTik RouterOS. Both are reportedly being actively exploited in the wild.

IFF Assessment

FOE

The active exploitation of these vulnerabilities by malicious actors poses a direct threat to organizations, making it bad news for defenders.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 28, 2026. Known ransomware use: Unknown.

Defender Context

Organizations using Microsoft SharePoint and MikroTik RouterOS should prioritize patching these vulnerabilities immediately due to active exploitation. Defenders should monitor their environments for any signs of compromise related to these specific CVEs and review their security posture for similar code injection or router compromise risks.

Read Full Story →