CISA Flags Exploited SharePoint and MikroTik Flaws

What happened
On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that attackers are already using them against real targets. One is CVE-2026-65660 (CVSS 8.8), a code injection flaw in Microsoft Office SharePoint. The other affects MikroTik RouterOS, the operating system behind a lot of inexpensive edge routers and wireless gear. The reporting comes via feeds.feedburner.com: SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild.
A KEV listing is a meaningful signal. CISA does not add entries for theoretical risk; it adds them when exploitation has been observed. Federal agencies get a hard remediation deadline, and while private businesses do not, the practical message is the same: if you run on-premises SharePoint or MikroTik network equipment, treat this as an emergency patch cycle rather than a routine one. We are not going to guess at specific patch version numbers or the exact MikroTik CVE details here, so verify current fixed builds directly with Microsoft's advisory for CVE-2026-65660 and with MikroTik's release notes before you touch anything.

Why this matters for Pittsburgh SMBs
Two very specific patterns make this relevant to the companies we work with across Allegheny, Butler, Washington, and Westmoreland counties.
First, on-prem SharePoint is stubbornly common in this market. Plenty of local CPA firms, law practices, engineering shops, and manufacturers moved email to Microsoft 365 years ago but left a SharePoint Server or an old intranet farm running in the server closet because a document workflow, a records retention scheme, or a line-of-business integration depended on it. Those servers are frequently reachable from the internet through a legacy extranet or VPN-adjacent path, and they are almost always full of exactly what attackers want: client files, engagement letters, matter documents, PHI, drawings, and pricing. A code injection flaw on that box is not a nuisance; it is a data breach with notification obligations attached. If you handle protected health information or are subject to HIPAA, SOC 2, or FTC Safeguards expectations, an unpatched, actively exploited server is also the kind of finding that turns an incident into a regulatory problem.
Second, MikroTik gear shows up in small-business networks more often than owners realize. It is capable, affordable hardware, and it frequently arrives by way of a prior IT vendor, a building's shared internet service, a warehouse wireless bridge, or a remote site someone stood up quickly. Edge devices get forgotten because they "just work" and nobody wants to schedule the outage. A compromised router gives an attacker persistent, credential-harvesting visibility into all of your traffic and a beachhead that endpoint tooling on laptops will never see.
For defense contractors in the region, add a compliance dimension. Under CMMC Level 2 and DFARS obligations, vulnerability management and timely remediation are assessable practices, not best-effort goals. If CUI passes anywhere near an unpatched SharePoint farm or an unmanaged edge router, that is a documented gap an assessor will find.
What to do about it this week
- Inventory before you patch. Confirm, in writing, whether you run any on-premises SharePoint Server or SharePoint-dependent intranet, including retired-but-powered-on servers. Do the same for MikroTik devices at headquarters, branch offices, warehouses, and home offices of key staff. If you cannot produce that list today, that is the first finding.
- Check the vendor advisories and apply the fixes. Pull the current guidance for CVE-2026-65660 from Microsoft and the corresponding RouterOS release from MikroTik, verify the fixed version applies to your exact build, snapshot or back up first, then patch. Do not rely on a summary article for version numbers.
- Take exposed systems off the public internet. If a SharePoint farm or a router management interface is reachable from outside, restrict it now to internal networks or a VPN while you schedule remediation. Reducing exposure buys time that patching alone does not.
- Hunt for signs you were already hit. Review SharePoint application and IIS logs for unexpected requests and new files, check for unfamiliar scheduled tasks and service accounts, and on MikroTik devices look for unrecognized admin users, scripts, scheduler entries, and firewall or DNS changes. Escalate anything odd to your cybersecurity team rather than "cleaning it up."
- Rotate credentials on affected systems. Local admin passwords, service accounts, router admin logins, and any API keys stored on those servers. Assume exposure on anything a compromised host could read.
- Close the process gap, not just the CVE. Make sure servers and network appliances are enrolled in your patch management program with defined windows and reporting, and that KEV additions trigger an out-of-band review. Firmware on edge devices needs an owner and a schedule.
- Consider retiring the on-prem farm. If SharePoint Server exists only for legacy reasons, migration to SharePoint Online removes a whole class of internet-facing risk and simplifies your technology roadmap. Scope it now, while the business case is obvious, rather than after the next advisory.
If you want a target: complete steps 1 through 3 by Friday, October 2, 2026, and steps 4 through 6 within 30 days, by October 26, 2026.
How we help
Our managed IT and security practice exists for weeks like this one: asset inventory you can trust, patch and firmware management that covers servers and edge devices, managed detection and response, and vCIO guidance that maps remediation to your HIPAA, SOC 2, FTC Safeguards, or CMMC obligations instead of leaving you to translate a CVE into an audit answer. If you are not certain whether you still run on-prem SharePoint or what brand of router sits in your wiring closet, that uncertainty is the real risk, and we can resolve it quickly.
Call us at 724.888.7007 or reach out through the contact form and we will scope a vulnerability and exposure review for your environment.
Related reading

Passkey Phishing Is Now Targeting Microsoft 365 Tenants
Microsoft disclosed passkey-themed phishing and CEO fraud campaigns hitting cloud tenants. Here is what Pittsburgh SMBs should verify in M365 this week.

Passkey-Themed Phishing Is Now Hitting Microsoft 365 Accounts
Microsoft warns extortion groups are using passkey and SSO-themed phishing to steal Microsoft 365 data. What Pittsburgh SMBs should verify and fix this week.

Fake IT Help Desk Calls Are Targeting Microsoft 365 Executives
Attackers are calling executives while posing as IT help desk to steal Microsoft 365 sessions. Here is what Pittsburgh SMBs should verify and change this week.