Imagine your house has a hidden, unlocked window that hackers just discovered, and now they're actively using it to sneak in. That's essentially what happened with two recent security flaws, one in Microsoft SharePoint and another in MikroTik RouterOS, which the U.S. Cybersecurity and Infrastructure Security Agency (CISA) just flagged as being actively exploited.

Let's break down what these are. First, there's CVE-2026-65660, a security hole in Microsoft SharePoint, which is a tool many businesses use for teamwork, document sharing, and hosting internal websites. This particular flaw is a "code injection vulnerability," meaning a hacker could sneak their own malicious instructions into the system, potentially taking control or stealing information. Think of it like someone finding a way to insert their own commands into your smart home system, making it do things you didn't intend.

The other vulnerability, CVE-2023-30799, affects MikroTik RouterOS, the operating system that runs many MikroTik network routers. Routers are the traffic cops of the internet, directing data to and from your devices. This flaw allows hackers to run their own code on the router, giving them unauthorized access. If a hacker can control your router, they could potentially snoop on your internet traffic, redirect you to fake websites, or even use your network to launch other attacks.

Why does this matter to you? If your workplace uses SharePoint or if your internet service provider (ISP) or a business you interact with uses MikroTik routers, these flaws are a direct threat to their security, and by extension, your data. CISA adding these to their "Known Exploited Vulnerabilities" (KEV) catalog is like a five-alarm fire drill; it means these aren't just theoretical problems, but ones hackers are actually using right now.

This news highlights a persistent cat-and-mouse game in cybersecurity: as companies build and update software, new weaknesses are inevitably discovered, and bad actors are always looking for ways to exploit them. For businesses, the immediate takeaway is clear: if you use SharePoint or MikroTik products, check for patches or updates immediately and apply them. Ignoring these warnings is like leaving your front door wide open after you’ve been told burglars are in the neighborhood.

Actively exploited vulnerabilities demand immediate attention and patching to protect data and systems.