CISA Flags Active Exploitation of SharePoint and MikroTik Router Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-65660, is a code injection flaw in Microsoft SharePoint. The second, CVE-2026-67279, affects MikroTik RouterOS and involves improper enforcement of workflow behaviour.
Both SharePoint and MikroTik routers are widely used by businesses of all sizes, including in Australia, making these vulnerabilities relevant well beyond US government networks. While CISA's binding directive requiring rapid patching only applies to US federal agencies, the agency is encouraging all organisations worldwide to prioritise fixing KEV-listed vulnerabilities because they represent flaws that criminals are already using in real attacks, not just theoretical risks.
Organisations running SharePoint servers or MikroTik routers should check vendor advisories immediately, apply available patches, and review whether their systems may have been compromised before patching was completed.