Cybersecurity agencies warn of active exploits in Microsoft SharePoint and Mikrotik routers as attacks on critical infrastructure rise

Global cybersecurity threats intensified on Friday as authorities and researchers flagged active exploitation of critical vulnerabilities and rising attacks on essential infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency added two flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint with a CVSS score of 8.8, and CVE-2026-67279, an improper enforcement flaw in Mikrotik RouterOS with a score of 6.9. Microsoft confirmed evidence of attacks exploiting the SharePoint flaw, which it updated from a spoofing vulnerability to one enabling remote code execution . CERT Polska reported that CVE-2026-67279, chained with CVE-2026-86060, allowed unauthenticated attackers to gain full administrative control of exposed Mikrotik routers .
Meanwhile, Luca Tagliaretti, executive director of the European Cybersecurity Competence Centre, warned at the CyberShield forum in Riga that critical infrastructure is increasingly targeted as a tool of geopolitical pressure. He cited data showing 80 to 85 percent of cyberattacks in Ukraine target civilian infrastructure, including energy, transportation, and public services, with similar trends observed in Europe .
In Latvia, Cert.lv reported persistent vulnerabilities in phishing defenses after 15,436 simulated phishing emails were sent in 2025, with 31.48 percent opened and credentials entered in 3,032 cases. The organization also identified 82 vulnerabilities in IT systems, including critical flaws enabling unauthorized access to user data .
Follow us for live European news
- 1
- 1
- 1
- 1
- 1
12 further sources not geolocated
