York Computer logo York Computer
Managed IT & Security
Cybersecurity News

CISA Flags Actively Exploited SharePoint and MikroTik Router Flaws — Patch This Week

York Computer •

On September 25, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two new vulnerabilities to its Known Exploited Vulnerabilities catalog — one in Microsoft SharePoint and one in MikroTik RouterOS — after confirming attackers are already using them in the wild. Both products are common in small-business environments: SharePoint underpins many Microsoft 365 file-sharing setups, and MikroTik routers sit at the edge of countless small offices. If either is on your network unpatched, you are on the clock.

What CISA actually added

CISA added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-65660, a Microsoft SharePoint code injection vulnerability, and CVE-2026-67279, a MikroTik RouterOS improper enforcement of behavioral workflow vulnerability.

In plain English: attackers have found a way to trick vulnerable SharePoint servers into running code they shouldn't, and a way to abuse MikroTik routers to bypass how the device is supposed to enforce rules. CISA notes these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise — and the same risk translates directly to any small business running the affected gear.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. Federal agencies are required to patch on a deadline; private-sector businesses aren't — but the KEV list is the single best free signal available for what attackers are actually using this week.

Why this matters for a small business

SharePoint is not just a SharePoint problem. If your office uses Microsoft 365 for shared files, team sites, or intranet pages, SharePoint is running under the hood. On-premises SharePoint servers — still common in law firms, medical practices, and manufacturers with older document-management setups — are the higher-risk target. Once an attacker gets code execution on a SharePoint server, they can typically move laterally into email, file shares, and identity systems.

MikroTik routers are popular with small businesses and IT contractors because they are inexpensive and flexible. That same install base makes them a favorite for ransomware crews and botnet operators. A compromised edge router lets an attacker watch traffic, redirect DNS, and open a permanent back door — usually without tripping any alarm inside your network.

This is exactly the kind of exposure a proper monitoring stack is supposed to catch, and it's a core reason to have a managed IT and cybersecurity partner watching your perimeter instead of hoping the router the last guy installed is still getting firmware updates.

What your IT provider should be doing this week

If you outsource IT — to York Computer or anyone else — here is what you should expect to see happen in the next few business days:

1. Inventory. They should already know whether you run on-prem SharePoint or SharePoint Server, and whether any MikroTik hardware sits on your network. If they can't answer in an hour, that's a red flag.

2. Patch and verify. Microsoft's SharePoint update and MikroTik's RouterOS fix both need to be applied, then confirmed — not just scheduled. "Patched" without a follow-up scan doesn't count.

3. Hunt for signs of prior compromise. Because these bugs are being actively exploited, patching alone isn't enough. Your provider should be checking SharePoint logs for unexpected code execution and router logs for unauthorized config changes or new admin accounts.

4. Reduce exposure. Internet-facing SharePoint and router management interfaces should not be reachable from the public web in the first place. If they are, that changes today.

For businesses with an internal tech person who's already stretched thin, this is exactly the workload that co-managed IT support is designed to absorb — the after-hours patching, KEV monitoring, and forensic checks that don't fit into a normal workday.

What York Businesses Should Do

York County businesses running on-premises SharePoint or MikroTik edge routers should get a written confirmation from their IT provider this week that both CVEs have been patched and logs reviewed. If no one is actively watching the CISA KEV list on your behalf, that gap is the story.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles