The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two significant vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, particularly affecting Microsoft SharePoint and MikroTik RouterOS. The most pressing of these is CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, which carries a high CVSS score of 8.8. This indicates a critical risk level, as evidence shows that these vulnerabilities are currently being exploited in the wild, posing a direct threat to organizations that utilize these platforms.
For businesses, the active exploitation of these vulnerabilities underscores the urgency of implementing robust security measures and timely patch management strategies. Organizations relying on Microsoft SharePoint must prioritize updating their systems to mitigate potential breaches that could lead to data loss or unauthorized access. Additionally, the vulnerabilities emphasize the broader implications for cybersecurity practices, suggesting that companies must remain vigilant against emerging threats and invest in comprehensive cybersecurity frameworks that include regular vulnerability assessments and employee training to recognize potential exploits. This situation serves as a stark reminder of the evolving threat landscape in cybersecurity, particularly as reliance on cloud-based services and network devices continues to grow in the digital age.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html)*