EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

CISA ha aggiunto due vulnerabilità, CVE-2026-65660 e CVE-2026-67279, al KEV catalog, segnalando sfruttamento attivo. La prima consente esecuzione di codice remoto su SharePoint, la seconda permette accesso non autenticato a router MikroTik. L'attacco MikroTrick combina due vulnerabilità per ottenere controllo totale. Patch disponibili, ma tempo limitato per le FCEB.

Why it matters

Le PMI italiane sono a rischio di attacchi che possono portare a compromissione di dati e controllo totale su dispositivi critici. La mancanza di patch potrebbe esporre infrastrutture a danni economici e operativi significativi.

Potential operational benefits

  • Riduzione della superficie esposta a attacchi remoti
  • Minimizzazione del rischio di accesso non autorizzato
  • Miglioramento del controllo su dispositivi e servizi critici
  • Aumento della visibilità e della risposta agli eventi di sicurezza
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMFA / IdentitàSegmentazione di reteMonitoraggio / SIEM
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
26/09/2026 10:49
MITRE ATT&CK
T1190, T1486, T1078
CVE
CVE-2026-65660
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source