Act
active
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited (CISA KEV)
- Engineer — Act: SharePoint (CVE-2026-65660, CVSS 8.8) is CISA KEV-listed, has a public PoC, and is seeing active exploitation — patch immediately per Microsoft’s advisory. Also audit MikroTik RouterOS firmware versions and apply vendor patches for the co-listed flaw.
- SOC/IR — Act: Active exploitation of both SharePoint and MikroTik RouterOS means assume-breach posture for those surfaces: hunt SharePoint access logs for code-injection patterns and sweep network edge devices running RouterOS for anomalous outbound connections or config changes since the KEV listing date.
- Leader — Plan: Confirm whether SharePoint and MikroTik RouterOS appear in your asset inventory and verify engineering teams are tracking CISA BOD remediation timelines; no board-level communication required unless your sector has seen confirmed targeting or you are under federal compliance obligations.
- Signals: CVE-2026-65660 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.