The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated two critical vulnerabilities to emergency status, adding actively exploited flaws in Microsoft SharePoint Server and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The move mandates immediate patching for federal agencies and signals a high-priority warning to all organizations.

By including these weaknesses in the KEV, CISA triggers its Binding Operational Directive 22-01. This directive legally requires Federal Civilian Executive Branch (FCEB) agencies to remediate the flaws within set deadlines. The agency consistently urges private sector organizations worldwide, including those in Hong Kong, to adopt these deadlines as a critical benchmark for their own security.

The first flaw, CVE-2026-65660, is a code injection vulnerability in Microsoft SharePoint Server. It grants an authenticated attacker with low-level privileges the ability to execute arbitrary code on the server. This could allow a threat actor, perhaps starting with a single compromised user account from a phishing attack, to take full control of a SharePoint server, leading to data theft or a launch point for broader network compromise. SharePoint is a staple collaboration platform across many enterprises.

The second vulnerability targets Mikrotik RouterOS, the software powering a vast number of routers used by service providers, businesses, and branch offices globally. While a specific CVE identifier was not detailed in the initial advisory, attacks at the network routing layer are particularly severe. Successful exploitation can provide attackers with persistent, covert access to core infrastructure, enabling traffic interception, service disruption, or a pivot point for further attacks within a network.

The KEV listing is a clear indicator that these vulnerabilities are not theoretical; they are being actively exploited in real-world attacks. This transitions them from routine updates to mandatory emergency actions.

For IT administrators and security teams, the response plan is immediate and defined:

  1. Locate Affected Systems: Conduct an urgent inventory to identify all instances of Microsoft SharePoint Server and devices running Mikrotik RouterOS within your environment.
  2. Deploy Security Patches: Immediately obtain and apply the official security updates from Microsoft and Mikrotik vendor advisories for all identified systems.
  3. Conduct Log Reviews: Scrutinize network and system logs for any anomalous activity or indicators of compromise associated with these platforms.
  4. Establish Continuous Monitoring: Make it a standard practice to follow CISA's KEV catalog and vendor security bulletins to manage future critical threats proactively.

This dual alert highlights the persistent danger to both collaborative business software and foundational internet infrastructure. The directive's urgency is particularly stark for widespread Mikrotik deployments and for SharePoint servers, which are common high-value targets. Organizations should treat the federal remediation deadlines as a non-negotiable minimum for their own patch management cycles.


美國網絡安全和基礎設施安全局 (CISA) 已將兩個關鍵漏洞的嚴重級別提升至緊急狀態,並將 Microsoft SharePoint Server 與 Mikrotik RouterOS 中已被積極利用的缺陷納入其已知遭利用漏洞 (KEV) 目錄。此舉要求聯邦機構立即進行修補,並向所有組織發出高度優先的警告。

透過將這些弱點納入 KEV,CISA 啟動了其具有約束力的運營指令 22-01。該指令在法律上要求聯邦民事行政部門 (FCEB) 機構在設定的期限內修補漏洞。該機構持續敦促全球私營部門組織,包括香港的組織,將這些期限視為其自身安全規劃的關鍵基準。

第一個漏洞是 CVE-2026-65660,這是 Microsoft SharePoint Server 中的一個程式碼注入漏洞。它允許具有低權限的認證攻擊者在伺服器上執行任意程式碼。這可能使威脅行為者(或許是從一次釣魚攻擊中獲取一個被入侵的使用者帳戶開始)完全控制一個 SharePoint 伺服器,導致資料竊取或作為更廣泛網路入侵的跳板。SharePoint 是眾多企業中的核心協作平台。

第二個漏洞針對的是 Mikrotik RouterOS,這是驅動全球服務供應商、企業及分支機構所使用的大量路由器的軟體。雖然初始公告中未提供具體的 CVE 標識符,但針對網路路由層面的攻擊尤其嚴重。成功利用可為攻擊者提供對核心基礎設施的持久、隱蔽訪問權限,從而進行流量攔截、服務中斷,或作為網路內進一步攻擊的樞紐點。

KEV 上的清單明確表明這些漏洞並非理論性的;它們已在現實世界的攻擊中被積極利用。這將它們從常規更新轉變為強制性的緊急行動。

對於 IT 管理員和安全團隊而言,應對方案明確且需立即執行:

  1. 定位受影響系統: 進行緊急清點,識別您環境中的所有 Microsoft SharePoint Server 實例以及運行 Mikrotik RouterOS 的設備。
  2. 部署安全補丁: 立即從 Microsoft 和 Mikrotik 供應商的安全公告中獲取官方安全更新,並應用於所有已識別的系統。
  3. 進行日誌審查: 仔細檢查網路和系統日誌,查找與這些平台相關的任何異常活動或入侵指標。
  4. 建立持續監控: 將追蹤 CISA 的 KEV 目錄和供應商安全公告作為標準實踐,以便主動管理未來的關鍵威脅。

這項雙重警報凸顯了對協作型商業軟體和基礎互聯網基礎設施的持續威脅。該指令的緊迫性對於廣泛部署的 Mikrotik 設備以及作為常見高價值目標的 SharePoint 伺服器尤為嚴峻。各組織應將聯邦修補期限視為其自身補丁管理週期中不可協商的最低標準。

新聞來源 / Original News Source