Active SharePoint and MikroTik Exploits Trigger Emergency Actions and Kiteworks Shutdown Call
Attackers are exploiting a remote code execution flaw in Microsoft SharePoint and chaining a MikroTik RouterOS vulnerability to gain full admin access to routers, while secure file-transfer firm Kiteworks has asked customers to power systems down for nine hours after federal intelligence warned of possible targeting.
Enterprise networks are facing simultaneous pressure from active exploits and a pre-emptive shutdown order affecting a widely used file-transfer product.
Security reports say attackers are exploiting a Microsoft SharePoint vulnerability that allows remote code execution, giving them the ability to run their own commands on exposed servers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also highlighted a MikroTik RouterOS flaw that’s being used in a chain of attacks to grant unauthenticated attackers full administrative control over vulnerable routers.
SharePoint is a common document management and collaboration platform in companies and government agencies. A remote code execution bug there can open a path to sensitive files and internal systems. MikroTik routers sit at the edge of many networks; full admin access lets an intruder reroute traffic, monitor communications or conscript devices into botnets.
In a separate move, secure file-transfer provider Kiteworks has told customers to shut systems down for nine hours after U.S. federal intelligence warned that a threat actor may target some of its platforms. The company said it has found no evidence of compromise and advised customers to upgrade to version 9.5.1.
For IT and security teams, these alerts mean urgent patching, checks for signs of intrusion and, in Kiteworks’ case, planned downtime that disrupts routine data exchange. Organizations that haven’t tracked their SharePoint instances, MikroTik deployments or Kiteworks appliances closely may struggle just to identify what needs immediate action.
Key developments to watch are vendor advisories and patches from Microsoft and MikroTik, any confirmation that the Kiteworks threat has moved from warning to active exploitation, and whether CISA adds the SharePoint and MikroTik vulnerabilities to its catalog of known exploited flaws with tight federal remediation deadlines.
Sources
- OSINT