$ techbeacon▋
CVE & Exploits

CISA Flags New SharePoint and RouterOS Flaws as Actively Exploited Threats

CISA Flags New SharePoint and RouterOS Flaws as Actively Exploited Threats

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Wednesday that it has added two critical security weaknesses – one affecting Microsoft SharePoint and another targeting MikroTik RouterOS – to its Known Exploited Vulnerabilities (KEV) catalog, signaling that threat actors are already leveraging these bugs in the wild.

CISA’s KEV list is a curated inventory of software flaws that have been observed in active attacks, and inclusion signals a heightened risk to both public and private sector networks. By publishing the vulnerabilities, the agency aims to accelerate remediation efforts, urging organizations to prioritize patches and mitigation steps before attackers can cause further damage.

The SharePoint vulnerability pertains to the popular collaboration platform used by countless enterprises for document management and internal communication. Security researchers have identified a flaw that could enable remote code execution or unauthorized data access if an attacker successfully exploits it, especially in environments where the service is exposed to the internet or poorly segmented.

In parallel, the MikroTik RouterOS issue concerns a series of weaknesses in the operating system that powers many of the company’s routers and wireless devices. These flaws can be abused to gain unauthorized control over network infrastructure, potentially allowing adversaries to intercept traffic, launch man‑in‑the‑middle attacks, or pivot deeper into corporate networks.

Both Microsoft and MikroTik have issued advisories urging customers to apply the latest security updates. CISA’s addition of these bugs to the KEV catalog underscores the agency’s broader push to improve the nation’s cyber resilience, reminding organizations that timely patch management remains a cornerstone of defense. Analysts expect that the public disclosure will spur a wave of patch deployments in the coming weeks, as enterprises scramble to close the newly highlighted gaps before additional exploit kits emerge.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related