Microsoft SharePoint and Mikrotik RouterOS face active exploitation following CISA's addition of two critical vulnerabilities to its Known Exploited Vulnerabilities catalog on Friday. The U.S. Cybersecurity and Infrastructure Security Agency confirmed these flaws are being actively weaponized in the wild, signaling immediate risk to thousands of organizations running these systems.

CVE-2026-65660 affects Microsoft Office SharePoint and carries a CVSS score of 8.8, denoting a high-severity flaw. The vulnerability stems from a code injection weakness that allows attackers to execute arbitrary code within SharePoint environments. SharePoint deployments span enterprise networks globally, making this vulnerability a widespread threat. Organizations running on-premises or hybrid SharePoint instances face direct exposure. An attacker exploiting this flaw gains the ability to execute commands with SharePoint service account privileges, potentially leading to data exfiltration, lateral movement across the network, or deployment of persistent backdoors.

The second vulnerability targets Mikrotik RouterOS, the operating system powering network access points and routers deployed across enterprises and service provider networks. Mikrotik hardware represents the backbone of connectivity infrastructure in countless organizations, placing this flaw in a critical position. Routers compromised through this vulnerability could enable attackers to intercept network traffic, redirect users to malicious sites, or serve as pivot points for network-wide compromise.

CISA's addition of both flaws to the KEV catalog carries operational weight. The agency maintains this list specifically for vulnerabilities where active exploitation evidence exists. Organizations operating critical infrastructure, federal systems, or essential services face compliance obligations under CISA guidelines to remediate KEV-listed vulnerabilities within defined timeframes. Federal contractors and government agencies typically must address these flaws within 30 days of catalog inclusion.

The timing creates urgency. Active exploitation means threat actors already possess working code or techniques to compromise these systems. Organizations that delay patching become targets for coordinated attacks. The exploitation likely reaches beyond opportunistic scanning. Financially motivated threat groups, state-sponsored actors, or ransomware operators frequently exploit known flaws in widely deployed systems to establish initial network access.

SharePoint administrators should prioritize patching immediately. Microsoft typically addresses critical vulnerabilities through out-of-band updates or scheduled monthly patches. Administrators without patch management infrastructure should implement network segmentation to limit SharePoint exposure and monitor authentication logs for suspicious activity indicative of exploitation attempts.

Mikrotik users face similar urgency. RouterOS updates require careful planning due to potential network downtime, but delaying patches leaves networks open to compromise. Organizations should establish maintenance windows to deploy patched versions. Administrators lacking immediate patching capability should monitor router logs for suspicious command execution or unexpected configuration changes.

Detection requires log analysis and endpoint visibility. For SharePoint, monitor application event logs for code injection attempts, unusual process execution spawned by W3WP.exe, or unexpected outbound connections from SharePoint servers. For Mikrotik, review router logs for firmware updates, script execution, or configuration alterations from unexpected sources.

Vulnerability databases and threat intelligence feeds will soon publish technical details and proof-of-concept code as researchers examine these flaws. Organizations should subscribe to security advisories from both Microsoft and Mikrotik for patch release notifications.