CISA has added two unrelated but actively exploited flaws to its Known Exploited Vulnerabilities catalog this week: a code-injection bug in on-premises Microsoft SharePoint (CVE-2026-65660, CVSS 8.8) and a pair of chained flaws in MikroTik's RouterOS, nicknamed "MikroTrick" (CVE-2026-67279 and CVE-2026-86060, CVSS 6.9). Federal agencies in the US have until 28 September 2026 to patch both. That deadline only binds US government systems, but CISA's KEV list is a reliable "this is being exploited right now, not just theoretical" signal for everyone else too.
The SharePoint flaw affects on-premises SharePoint Server 2016, 2019, and Subscription Edition — not SharePoint Online in Microsoft 365 — and lets an authenticated attacker who already has some foothold escalate to running code on the server. The MikroTik chain is more alarming for anyone running one of these routers at the network edge: combining the two bugs gives an attacker with no credentials at all full administrative control of an internet-exposed device, which is exactly the kind of hardware small offices and ISPs use to route their traffic. Researchers report both flaws are already being actively probed and exploited in the wild, not just theorized.
What this means for your business
If your organisation runs on-premises SharePoint rather than the cloud-hosted Microsoft 365 version, confirm with whoever manages that server that the September security update has been applied — this is not the kind of patch to leave for the next maintenance window. If you or your IT provider use MikroTik routers for office internet, guest Wi-Fi, or site-to-site links, check the device's management interface is not exposed to the public internet and that RouterOS is updated to a fixed version; an unauthenticated router takeover can let an attacker intercept, redirect, or snoop on everything that crosses your network. Neither flaw needs a sophisticated attacker to exploit — that combination of "easy to exploit" and "already on CISA's active list" is exactly why both earned a deadline this week.