CuraSec

Act active

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited (CISA KEV)

2026-09-26 14:58 UTC · The Hacker News · read the source ↗ #sharepoint#mikrotik#cisa-kev
  • Engineer — Act: SharePoint (CVE-2026-65660, CVSS 8.8) is CISA KEV-listed, has a public PoC, and is seeing active exploitation — patch immediately per Microsoft’s advisory. Also audit MikroTik RouterOS firmware versions and apply vendor patches for the co-listed flaw.
  • SOC/IR — Act: Active exploitation of both SharePoint and MikroTik RouterOS means assume-breach posture for those surfaces: hunt SharePoint access logs for code-injection patterns and sweep network edge devices running RouterOS for anomalous outbound connections or config changes since the KEV listing date.
  • Leader — Plan: Confirm whether SharePoint and MikroTik RouterOS appear in your asset inventory and verify engineering teams are tracking CISA BOD remediation timelines; no board-level communication required unless your sector has seen confirmed targeting or you are under federal compliance obligations.
  • Signals: CVE-2026-65660 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.