Cybersecurity experts have sounded the alarm over a pair of serious vulnerabilities that are being actively exploited in the wild. A Remote Code Execution (RCE) flaw in Microsoft’s SharePoint platform, combined with an exploit for MikroTik RouterOS, is allowing attackers to gain unauthorized access to sensitive data and systems.
The RCE vulnerability in SharePoint, which was patched by Microsoft in July, allows attackers to inject malicious code into the platform. When exploited in conjunction with a bug in MikroTik’s RouterOS software, attackers can gain elevated privileges on affected networks, essentially granting them free rein to move laterally within an organization’s internal systems.
This exploit sequence is particularly concerning because it relies on common and often overlooked vulnerabilities that are frequently present in networks. Many organizations have not yet patched their SharePoint installations or upgraded their MikroTik RouterOS software, leaving themselves exposed to potential breaches. Furthermore, the ease with which these flaws can be exploited means that attackers do not need sophisticated tools or expertise to carry out an attack.
One of the most significant concerns surrounding this exploit is its ability to bypass security controls and move undetected through a network. By exploiting the privilege escalation flaw in MikroTik RouterOS, attackers can sidestep traditional security measures such as firewalls and intrusion detection systems. This makes it challenging for defenders to detect and respond to an attack in real-time.
The exploitation of these vulnerabilities also highlights a fundamental issue in modern cybersecurity: the interconnectedness of systems. Organizations often fail to consider the potential risks associated with integrating multiple platforms, applications, or services within their networks. In this case, the combination of SharePoint’s RCE flaw and the MikroTik RouterOS bug creates an exploitable vulnerability that can be used to gain access to sensitive data and systems.
The affected organizations are wide-ranging, including those in the finance, healthcare, and education sectors, among others. This means that any organization using these platforms or software should take immediate action to address the vulnerabilities by applying the necessary patches and updates.
To mitigate this risk, we recommend that network administrators prioritize patching and updating their systems immediately. Conducting thorough vulnerability assessments can also help identify potential entry points for attackers. In addition, organizations should consider implementing additional security measures such as advanced threat detection tools or penetration testing to simulate real-world attack scenarios. By taking proactive steps now, defenders can minimize the risk of an exploited attack and ensure that their networks remain secure in the face of emerging threats.
Source: The Hacker News — 2026-09-26