$ techbeacon▋
CVE & Exploits

CISA Flags Microsoft SharePoint and MikroTik RouterOS Bugs as Actively Exploited

CISA Flags Microsoft SharePoint and MikroTik RouterOS Bugs as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Friday that two critical security flaws—one affecting Microsoft SharePoint and another targeting MikroTik RouterOS—have been placed on its Known Exploited Vulnerabilities (KEV) catalog after confirming they are being leveraged in active attacks.

The SharePoint issue is a remote‑code‑execution (RCE) vulnerability that allows unauthenticated attackers to execute arbitrary commands on vulnerable servers. Because SharePoint is widely deployed for document management and collaboration across government agencies and private enterprises, a successful exploit could grant attackers footholds deep within corporate networks.

The second entry concerns a serious RCE weakness in MikroTik’s RouterOS operating system, which powers a large share of broadband and enterprise routers worldwide. Exploitation of this flaw can enable threat actors to take control of networking equipment, potentially intercepting traffic, disrupting services, or using the compromised routers as launch points for broader intrusions.

CISA’s KEV list is intended to highlight vulnerabilities that have been observed in the wild and that pose an imminent risk to U.S. critical infrastructure. Inclusion signals that federal agencies must prioritize remediation, and it serves as a warning to the broader community that these flaws are no longer theoretical.

Both vulnerabilities arrive amid a broader trend of attackers focusing on widely used collaboration tools and networking hardware. Recent campaigns have demonstrated that compromising a single server or router can provide a pathway to lateral movement, data exfiltration, or ransomware deployment, underscoring why rapid patching is essential.

Security teams are urged to apply the latest patches released by Microsoft and MikroTik without delay, enable any available mitigations such as network‑level filtering, and monitor for indicators of compromise associated with known exploit kits. Organizations that cannot patch immediately should consider temporary controls, including disabling affected services or restricting external access.

Looking ahead, CISA indicated that it will continue to track exploitation activity and update the KEV catalog as new evidence emerges. The agency’s move reflects an ongoing effort to push timely vulnerability management and to reduce the attack surface that adversaries exploit across both software and hardware ecosystems.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related