CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑65660, CVE‑2026‑67279) to KEV Catalog
What It Is – The Cybersecurity and Infrastructure Security Agency (CISA) announced that two vulnerabilities—Microsoft SharePoint code‑injection (CVE‑2026‑65660) and MikroTik RouterOS workflow enforcement flaw (CVE‑2026‑67279)—have been confirmed as actively exploited and are now listed in the agency’s Known Exploited Vulnerabilities (KEV) Catalog.
Exploitability – Both CVEs have documented evidence of real‑world exploitation; CISA’s KEV inclusion signals that threat actors are already leveraging them against publicly exposed assets.
Affected Products – Microsoft SharePoint (on‑premises or online) and MikroTik RouterOS (various firmware versions).
Why It Matters for Trust & Control Assurance
- Vulnerability‑Management Control – Demonstrates the need for a continuous, risk‑based patch‑management process that can surface and remediate high‑impact flaws before they are weaponized.
- Evidence‑Based Auditing – Prioritizing KEV items provides defensible evidence of due‑diligence for auditors and regulators, showing that an organization actively tracks and mitigates the most dangerous exposures.
- Enterprise‑Wide Risk Posture – Aligns with the broader governance objective of maintaining a trusted digital supply chain; rapid remediation of KEV items reduces the attack surface that adversaries commonly exploit.
Recommended Actions
- Inventory all SharePoint servers and MikroTik devices on your network.
- Prioritize patching for CVE‑2026‑65660 and CVE‑2026‑67279 per CISA’s BOD 26‑04 guidance.
- Validate remediation through vulnerability scans and log‑based proof of patch deployment.
- Document the remediation steps in your vulnerability‑management system to create audit‑ready evidence.
- Monitor threat feeds for any new exploitation activity related to these CVEs.