The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, confirming that both flaws are being actively exploited by attackers.

SharePoint Code Injection Flaw

The Microsoft-related issue is tracked as CVE-2026-65660, carrying a CVSS score of 8.8. It is described as a code injection vulnerability in Microsoft Office SharePoint that can lead to remote code execution. The high severity score reflects the potential for attackers to run arbitrary code on affected SharePoint deployments, which are widely used for internal document management and collaboration in enterprise environments.

MikroTik RouterOS Vulnerability

CISA also flagged a separate flaw impacting MikroTik RouterOS, the operating system that powers a large base of network routers used by businesses and internet service providers worldwide. As with the SharePoint bug, this vulnerability has been confirmed to be under active exploitation, prompting its inclusion in the KEV catalog.

Why This Matters

Inclusion in CISA’s KEV catalog carries specific weight for U.S. federal civilian agencies, which are required under Binding Operational Directive 22-01 to remediate listed vulnerabilities within a mandated timeframe. While the directive technically applies to federal agencies, security teams across the private sector routinely treat KEV entries as a strong signal of real-world attacker interest and prioritize patching accordingly.

SharePoint servers are frequently exposed to the internet or accessible from broad internal networks, making them attractive targets for both initial access and lateral movement. Network infrastructure running RouterOS, meanwhile, often sits at the perimeter of an organization’s network, and a compromised router can serve as a foothold for further intrusion or as a platform for botnet activity.

Organizations running either Microsoft SharePoint or MikroTik RouterOS should treat these advisories as urgent. Security teams are advised to check for available patches, review exposure of affected systems, and monitor for indicators of compromise consistent with exploitation of these vulnerabilities.