Critical SharePoint & MikroTik Flaws Exploited: Patch Now or Risk Full Takeover
Two critical vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS are being actively exploited in the wild, prompting CISA to add them to its Known Exploited Vulnerabilities catalog. The SharePoint flaw enables remote code execution, while the MikroTik vulnerabilities can be chained together to allow unauthenticated attackers to fully take over network routers — a particularly dangerous scenario for organizations relying on these devices for critical infrastructure. The MikroTik attack chain is especially alarming because it requires no credentials, meaning exposed devices are effectively open to any threat actor who discovers them. These exploits highlight the persistent risk of unpatched internet-facing systems, where delayed remediation directly translates into attacker opportunity. Organizations without a mature, prioritized patching process for critical and internet-exposed assets are particularly vulnerable to these types of campaigns.
Tactical Insight
Immediate Actions
- Apply all available patches for CVE-2026-65660 (SharePoint) and CVE-2026-67279 / CVE-2026-86060 (MikroTik RouterOS) immediately.
- Audit internet-facing SharePoint and MikroTik devices and temporarily isolate or firewall any that cannot be patched right away.
- Verify CISA's KEV catalog against your asset inventory and treat any matches as P1 remediation priorities.
Long-term Improvements
- Establish a formal emergency patching SLA (e.g., 24–72 hours) for critical vulnerabilities appearing in CISA's KEV catalog.
- Maintain a continuously updated, accurate inventory of all network appliances, including firmware versions, to reduce patch blind spots.
- Implement network segmentation to isolate routers and collaboration platforms from sensitive internal systems, limiting lateral movement if compromise occurs.
Detection Measures
- Deploy continuous vulnerability scanning against all internet-facing assets and integrate results into your SIEM for real-time alerting.
- Monitor router and SharePoint logs for anomalous administrative access attempts, especially unauthenticated or off-hours activity.
- Subscribe to CISA KEV catalog alerts and threat intelligence feeds to receive early warning of newly exploited vulnerabilities relevant to your environment.