Home » Robotics » Attackers Are Already Inside: Active Exploitation Hits SharePoint and MikroTik Routers

Attackers Are Already Inside: Active Exploitation Hits SharePoint and MikroTik Routers

Attackers Are Already Inside: Active Exploitation Hits SharePoint and MikroTik Routers

Two serious vulnerabilities — one buried in Microsoft SharePoint and another in MikroTik’s RouterOS — have moved from proof-of-concept territory into live attacks, with threat actors actively exploiting both flaws against real targets. This is not a drill, and patching windows are closing fast. The Hacker News first reported the active exploitation, flagging both vulnerabilities as urgent remediation priorities for security teams. Given how broadly SharePoint is deployed across enterprise environments and how many ISPs and small businesses rely on MikroTik hardware, the attack surface here is enormous. If your organization runs either platform and hasn’t patched, assume the worst. Similar supply-chain and software risks have resurfaced repeatedly this year — including the malware-laced GitHub Actions campaign that quietly resumed attacks on developer pipelines after an initial takedown.

a rack-mounted enterprise server running Microsoft SharePoint in a dimly lit corporate data center aisle, indicator lights blinking amber

The SharePoint flaw is a remote code execution vulnerability, meaning an unauthenticated or low-privilege attacker can potentially run arbitrary commands on an exposed server without ever needing physical access. That category of bug sits at the top of the severity spectrum for a reason: successful exploitation can hand attackers a foothold inside an organization’s intranet, from which lateral movement, data exfiltration, and ransomware deployment all become significantly easier. SharePoint installations are everywhere — law firms, government agencies, healthcare systems, and Fortune 500 companies all depend on it for document management and internal collaboration, making any RCE flaw in the platform an automatic high-value target.

MikroTik RouterOS: The Hardware Angle Nobody Should Ignore

The MikroTik side of this story carries its own distinct danger profile. RouterOS powers a staggering number of routers and wireless systems deployed by ISPs, small businesses, and enterprise network administrators worldwide — MikroTik estimates millions of active installations globally. A flaw in that platform doesn’t just compromise one endpoint; it can compromise everything behind the router. Attackers who control a MikroTik device can intercept traffic, redirect DNS queries, or use the compromised hardware as a persistent relay node inside a victim’s network — invisible and difficult to detect without specific forensics tooling.

What makes the MikroTik vulnerability especially concerning is the device class itself. Routers and network appliances are notoriously slow to receive patches in the field. Many run outdated firmware versions for years, either because administrators don’t monitor vendor advisories or because updates require downtime that small operations can’t afford. Threat actors know this, which is why network edge devices have become a preferred staging ground for everything from nation-state intrusions to commodity botnet recruitment. The CISA vulnerability summary for the week of September 14, 2026 includes both flaws, reinforcing that federal cybersecurity authorities consider active exploitation confirmed and the threat level elevated.

a cluster of MikroTik routers mounted on a wall panel in a small network operations room, ethernet cables color-coded and labeled

What Security Teams Must Do Right Now

For SharePoint administrators, the immediate priority is identifying exposed instances — particularly any facing the public internet — and applying Microsoft’s available patch without waiting for a scheduled maintenance window. Organizations running SharePoint Server on-premises carry more direct risk than those using SharePoint Online, where Microsoft handles patching at the infrastructure layer, but both environments warrant auditing for indicators of compromise. Log reviews should focus on unusual authentication patterns, unexpected process spawning from SharePoint worker processes, and any outbound connections to unfamiliar IP ranges.

MikroTik administrators need to update RouterOS to the latest stable release immediately and audit device configurations for any unauthorized rules, scripts, or remote-access credentials that may have been injected by an attacker already inside. Disabling unnecessary services — particularly Winbox and API access exposed to the internet — reduces the attack surface while patching is underway. This back-to-basics guidance sounds straightforward, but given how often unpatched device flaws linger in production environments, it bears repeating loudly. The window between public disclosure and widespread exploitation has collapsed to days, sometimes hours. These two vulnerabilities are proof that adversaries are moving faster than most patch cycles allow.

Follow Future Wire

Subscribe to Future Wire!

Please choose one:

We don’t spam! Read our privacy policy for more info.

Subscribe to Future Wire!

Please choose one:

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *