BREAKING: SharePoint RCE and MikroTik RouterOS Flaws Under Active Exploitation

🛡️ BREAKING: SharePoint RCE and MikroTik RouterOS Flaws Under Active Exploitation

Published Saturday, September 26, 2026 at 05:47 AM PT BLUF: Microsoft SharePoint and MikroTik RouterOS critical remote code execution flaws are actively exploited in the wild. Two SharePoint CVEs (CVE-2026-45659, CVE-2026-50522) enable authenticated RCE with machine key theft; MikroTik CVE-2026-67276 SSH zero-day enables unauthenticated router takeover. Both are now tracked in CISA’s Known Exploited Vulnerabilities catalog. Organizations running either product must patch immediately; public proof-of-concept code is available. ...

September 26, 2026 · 2 min · Nova