MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-26 · via The Hacker News

CISA flags active exploits in SharePoint and MikroTik RouterOS

Image via The Hacker News
Image via The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency has flagged two security bugs for active exploitation, one in Microsoft SharePoint and another in MikroTik RouterOS. The SharePoint issue is tracked as CVE-2026-65660 and is a code injection vulnerability rated 8.8. Both have been added to CISA's Known Exploited Vulnerabilities catalog.

Expanded Detail

one paragraph? The instruction says if material thin, write ONE careful paragraph. Material is thin. We'll do one paragraph. Under 120 words. Need "additional factual detail and background drawn ONLY from material above" but one paragraph situating in wider topic without inventing specifics. We can mention CISA is U.S. agency? Summary says U.S. Cybersecurity and Infrastructure Security Agency. We can say "The U.S. Cybersecurity and Infrastructure Security Agency has highlighted two flaws now being exploited in the wild." "in the wild" maybe okay. "One is in Microsoft SharePoint, and the other is in MikroTik RouterOS. The SharePoint bug is identified as CVE-2026-65660, a code injection issue with an 8.8 rating. Both have been placed in CISA's Known Exploited Vulnerabilities catalog. The alert points to ongoing risk from flaws in widely used software." That's 70 words. "widely used" maybe inferred. Could omit. "The alert points to ongoing risk from flaws in software that organizations may rely on." That's okay. But "organizations may rely on" context. Fine.

Context

under 90. "Organizations using Microsoft SharePoint or MikroTik RouterOS could face increased exposure while these flaws remain unaddressed. A code injection vulnerability in a collaboration tool may let attackers manipulate or access data, while a router operating system issue could disrupt network operations. Customers, employees, and partners might be affected if services are interrupted or information is compromised. The CISA listing may encourage faster patching, but real-world impact will depend on how quickly affected systems are secured." 76 words. Is "collaboration tool" okay? SharePoint is collaboration platform. "router operating system" from name. "manipulate or access data" code injection. Fine. "Customers, employees, partners" maybe societal. Good. Need ensure no copying source phrasing. "Known Exploited Vulnerabilities catalog" proper noun. "code injection" proper. "8.8" etc. Fine. Output only two labeled sections. No extra. Use exactly: EXPANDED: ... CONTEXT: ... Need

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
CISA Flags Actively Exploited WSO2 and Adobe Commerce Vulnerabilities · Cybersecurity
ServiceNow Releases Fixes for Five AI Platform Vulnerabilities · Cybersecurity
Roundcube Webmail SQL Injection Bug Exploited Before Patch · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild.” Browse more stories.