The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are under active exploitation by threat actors. The advisory, covered by The Hacker News on 29 September 2026, targets foundational enterprise technologies: Microsoft SharePoint and MikroTik RouterOS.
The first flaw, tracked as CVE-2026-65660 with a CVSS score of 8.8, is a code injection vulnerability affecting on-premises Microsoft Office SharePoint installations. Successful exploitation could allow a remote attacker to execute arbitrary code on the server, potentially leading to a full system compromise, data theft, or deployment of further malware.
The second issue, CVE-2026-6012, impacts MikroTik's RouterOS, the firmware powering the company's line of networking routers. Details on the specific flaw type were not fully enumerated in the initial report, but its inclusion in the KEV catalog signifies it is being actively leveraged in the wild. Vulnerabilities in networking equipment like this often provide attackers with a persistent foothold on a network, enabling traffic interception, lateral movement, and further attacks on internal systems.
CISA's mandate is primarily for U.S. federal agencies, but the KEV catalog has become a de facto global benchmark for private-sector security teams. Its primary function is to prioritize vulnerabilities with confirmed exploitation, signaling that these are not theoretical risks but immediate threats demanding a response.
Microsoft's collaboration suite and MikroTik's networking hardware are widely deployed across enterprises and small-to-medium businesses globally. The active exploitation of flaws in such core infrastructure tools creates a significant risk of widespread compromise if patches are not applied promptly.
The core message from CISA and security analysts is clear: these vulnerabilities must be remediated with the highest priority. Organizations are urged to treat the KEV catalog entry as an urgent call to action, typically implying a two-week window for mitigation.
Recommended immediate actions for affected organizations:
-
For Microsoft SharePoint: System administrators must immediately verify that all on-premises or hybrid SharePoint servers are updated with the latest cumulative security patches from Microsoft. A concurrent audit of SharePoint configurations is critical to minimize unnecessary permissions and ensure management interfaces are not exposed to the public internet.
-
For MikroTik RouterOS: The firmware on all MikroTik devices should be updated to the latest stable version available from the vendor. As a vital hardening step, administrators should ensure that management interfaces (such as Winbox and WebFig) are disabled on all external-facing networks and are accessible only from secure, internal segments.
Security teams should integrate the CISA KEV catalog into their regular vulnerability management workflows, using it to flag the most severe and actively exploited flaws. Beyond patching, organizations that believe they may have already been compromised should review vendor-provided indicators of compromise (IOCs) and system logs for suspicious activity. The confirmation of active exploitation moves this from a standard patching cycle to a defensive emergency.
美國網絡安全與基礎設施安全局(CISA)已將兩個高嚴重性漏洞加入其已知被利用漏洞目錄,確認這些漏洞正遭受威脅行為者 active exploitation。The Hacker News 於 2026 年 9 月 29 日報導,此次安全公告針對企業基礎技術:Microsoft SharePoint 及 MikroTik RouterOS。
首個漏洞追蹤編號為 CVE-2026-65660,CVSS 評分為 8.8,是影響 Microsoft Office SharePoint 本機安裝版本的代碼注入漏洞。成功利用此漏洞可能允許遠端攻擊者在伺服器上執行任意代碼,進而導致全面系統入侵、數據被竊或植入更多惡意軟件。
第二個問題 CVE-2026-6012 影響 MikroTik 的 RouterOS,該韌體為該公司系列網絡路由器提供運行基礎。初步報告未完整列明具體漏洞類型,但其被列入 KEV 目錄表明正被在野 active exploitation。此類網絡設備的漏洞常為攻擊者提供網絡內的持久立足點,使其能攔截流量、進行橫向移動並進一步攻擊內部系統。
CISA 的指令主要針對美國聯邦機構,但 KEV 目錄已成為私營部門安全團隊實際採用的全球基準。其主要功能是優先處理已確認被利用的漏洞,表明這些並非理論性風險,而是需要立即應對的即時威脅。
Microsoft 的協作套件與 MikroTik 的網絡硬件在全球企業及中小型企業中廣泛部署。若未及時安裝補丁,這些核心基礎設施工具的 active exploitation 將造成大規模入侵的嚴重風險。
CISA 與安全分析師傳達的核心信息明確:必須以最高優先順序修補這些漏洞。組織應將 KEV 目錄的更新視為緊急行動號召,通常意味著需在兩週內完成緩解措施。
建議受影響組織立即採取的行動:
-
針對 Microsoft SharePoint:系統管理員必須立即核實所有本機或混合 SharePoint 伺服器已安裝 Microsoft 最新累積安全補丁。同時審計 SharePoint 配置至關重要,需減少不必要權限並確保管理介面未暴露於公開互聯網。
-
針對 MikroTik RouterOS:應將所有 MikroTik 設備的韌體更新至供應商提供的最新穩定版本。作為重要加固措施,管理員應確保管理介面(如 Winbox 和 WebFig)在所有外部網絡上停用,且僅可從安全的內部網段訪問。
安全團隊應將 CISA KEV 目錄整合至常規漏洞管理工作流程,用以標記最嚴重且 active exploitation 的漏洞。除修補外,懷疑可能已遭入侵的組織應查閱供應商提供的入侵指標(IOC)及系統日誌以偵測可疑活動。active exploitation 的確認使這已超越標準修補週期,成為防禦緊急事件。
