CISA Warns of Active Attacks on SharePoint and MikroTik
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security vulnerabilities in Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on Friday. This decision is based on evidence of active exploitation of these vulnerabilities in cybercrime. The first vulnerability, identified as CVE-2026-65660, is a code injection vulnerability in Microsoft Office SharePoint. It has a CVSS score of 8.8, making it a critical threat to affected systems.
Attackers can exploit this vulnerability to inject and execute malicious code, potentially leading to a complete compromise of the system. The second vulnerability affects MikroTik RouterOS and has also been actively exploited. Details regarding this specific vulnerability have not been disclosed by CISA; however, it is known that MikroTik RouterOS is used in many enterprise networks, increasing the potential reach of the attacks. CISA recommends that all users of Microsoft SharePoint and MikroTik RouterOS promptly install security updates to protect against potential attacks. The agency has emphasized that the exploitation of these vulnerabilities can lead to significant security risks, especially in critical infrastructures.
The vulnerability in SharePoint could be particularly dangerous for companies that rely on this platform for collaboration and document management. A successful attack could not only lead to data loss but also jeopardize the integrity of the entire IT infrastructure. CISA has already taken steps to inform affected organizations and assist them in implementing security solutions. The agency has also recommended reviewing network security and taking additional protective measures to minimize the impact of a potential attack. The discovery of these vulnerabilities comes at a time when cyberattacks on businesses and public institutions worldwide are increasing.
According to the Cybersecurity Report 2026, there was a 30% increase in reported security incidents in the first half of the year compared to the previous year. CISA has urged the IT community to remain vigilant and utilize all available resources to protect against these and other threats. The agency plans to provide further information and guidance to ensure the security of affected systems. The vulnerability CVE-2026-65660 is estimated by security experts to affect millions of systems worldwide that use Microsoft SharePoint. Therefore, companies should promptly review their systems and apply necessary updates to protect against potential attacks.
💬 Comentarii (0)
Inca nu exista comentarii. Fii primul!