Critical Code Injection in Microsoft SharePoint (CVE‑2026‑65660) and MikroTik RouterOS Flaws Actively Exploited
What It Is — CISA added two flaws to its Known Exploited Vulnerabilities (KEV) catalog: a code‑injection vulnerability in Microsoft SharePoint (CVE‑2026‑65660) with a CVSS 8.8 score, and a remote‑code‑execution issue in MikroTik RouterOS. Both have been observed in the wild, confirming active exploitation.
Exploitability — Public exploit code and network‑traffic indicators have been shared in underground forums; CISA’s KEV listing signals that attackers are already leveraging these bugs at scale.
Affected Products — Microsoft SharePoint (on‑premises and SharePoint Online) and MikroTik RouterOS (all supported releases prior to the vendor’s emergency patch).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a vulnerability‑management control that ensures timely identification, risk‑based prioritization, and remediation of high‑severity flaws.
- Continuous evidence of patch status becomes a defensible audit artifact when regulators or enterprise buyers request proof of due diligence.
- Unpatched RCE pathways erode the trust signal that an organization’s security posture is under active, measurable control.
Recommended Actions
- Deploy Microsoft’s security update for CVE‑2026‑65660 immediately; verify installation via your patch‑management system.
- Upgrade MikroTik RouterOS to the latest patched release; confirm the version on every router through automated inventory scans.
- Integrate the patch‑status data into a continuous‑monitoring dashboard that maps to the “Vulnerability Management” control objective.
- Conduct a rapid risk assessment to prioritize any downstream systems that may have been exposed.
Source: The Hacker News – SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild