By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds SharePoint and MikroTik Flaws to Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added two significant security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Friday, citing concrete evidence of their active exploitation in the wild. This inclusion mandates that federal agencies patch these vulnerabilities by specific deadlines to mitigate ongoing risks. The first vulnerability, identified as CVE-2026-65660, affects Microsoft Office SharePoint and carries a high severity score of 8.8 on the Common Vulnerability Scoring System (CVSS). This flaw is characterized as a code injection vulnerability, meaning attackers can potentially execute arbitrary code on affected SharePoint servers, leading to system compromise and data theft. The second vulnerability, impacting MikroTik RouterOS, is designated as CVE-2023-32350. While its specific CVSS score was not detailed in the initial announcement, its addition to the KEV catalog signifies that it is actively being weaponized by malicious actors. MikroTik RouterOS is a popular operating system used in routers manufactured by MikroTik, a company known for its networking hardware. Exploitation of this vulnerability could allow attackers to gain unauthorized access to or control over affected network devices, potentially disrupting network operations or facilitating further network intrusions. The KEV catalog is a crucial resource maintained by CISA, which lists vulnerabilities that have been confirmed to be actively exploited by threat actors. Inclusion in this catalog triggers mandatory remediation efforts for U.S. federal civilian executive branch (FCEB) agencies, requiring them to apply patches or implement mitigating controls within a specified timeframe, typically 15 days for critical vulnerabilities. This proactive measure aims to prevent widespread damage and protect critical infrastructure from known threats. The addition of these two vulnerabilities underscores the persistent threat landscape and the importance of timely security updates for widely used software and hardware. Organizations relying on Microsoft SharePoint for document management and collaboration, as well as those utilizing MikroTik devices for network infrastructure, are strongly advised to review their security postures and ensure these specific vulnerabilities are addressed immediately. The ongoing exploitation of such flaws highlights the need for continuous vulnerability management and rapid patching cycles to stay ahead of cyber adversaries. CISA's action serves as a critical alert to the broader cybersecurity community, emphasizing the real-world impact of these vulnerabilities and the necessity of robust defense strategies.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.