Government Advisory

CISA Flags Active Exploitation of SharePoint and MikroTik Router Flaws

CISA · 25 Sept 2026
Key Takeaway If your business runs Microsoft SharePoint or MikroTik routers, patch them now and check for signs of prior compromise, as these flaws are being actively exploited.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-65660, is a code injection flaw in Microsoft SharePoint. The second, CVE-2026-67279, affects MikroTik RouterOS and involves improper enforcement of workflow behaviour.

Both SharePoint and MikroTik routers are widely used by businesses of all sizes, including in Australia, making these vulnerabilities relevant well beyond US government networks. While CISA's binding directive requiring rapid patching only applies to US federal agencies, the agency is encouraging all organisations worldwide to prioritise fixing KEV-listed vulnerabilities because they represent flaws that criminals are already using in real attacks, not just theoretical risks.

Organisations running SharePoint servers or MikroTik routers should check vendor advisories immediately, apply available patches, and review whether their systems may have been compromised before patching was completed.

CISA SharePoint MikroTik vulnerability management KEV catalog

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.