Home › Intelligence › Brief
VULNERABILITY BRIEF 🟠 High Advisory

CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑65660, CVE‑2026‑67279) to KEV Catalog

CISA announced that Microsoft SharePoint (CVE‑2026‑65660) and MikroTik RouterOS (CVE‑2026‑67279) are now listed in its Known Exploited Vulnerabilities catalog, indicating active threat‑actor use. Organizations should prioritize patching to meet BOD 26‑04 risk‑based remediation expectations and maintain audit‑ready evidence.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
1 recommended
📰
Source
cisa.gov

CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑65660, CVE‑2026‑67279) to KEV Catalog

What It Is – The Cybersecurity and Infrastructure Security Agency (CISA) announced that two vulnerabilities—Microsoft SharePoint code‑injection (CVE‑2026‑65660) and MikroTik RouterOS workflow enforcement flaw (CVE‑2026‑67279)—have been confirmed as actively exploited and are now listed in the agency’s Known Exploited Vulnerabilities (KEV) Catalog.

Exploitability – Both CVEs have documented evidence of real‑world exploitation; CISA’s KEV inclusion signals that threat actors are already leveraging them against publicly exposed assets.

Affected Products – Microsoft SharePoint (on‑premises or online) and MikroTik RouterOS (various firmware versions).

Why It Matters for Trust & Control Assurance

  • Vulnerability‑Management Control – Demonstrates the need for a continuous, risk‑based patch‑management process that can surface and remediate high‑impact flaws before they are weaponized.
  • Evidence‑Based Auditing – Prioritizing KEV items provides defensible evidence of due‑diligence for auditors and regulators, showing that an organization actively tracks and mitigates the most dangerous exposures.
  • Enterprise‑Wide Risk Posture – Aligns with the broader governance objective of maintaining a trusted digital supply chain; rapid remediation of KEV items reduces the attack surface that adversaries commonly exploit.

Recommended Actions

  1. Inventory all SharePoint servers and MikroTik devices on your network.
  2. Prioritize patching for CVE‑2026‑65660 and CVE‑2026‑67279 per CISA’s BOD 26‑04 guidance.
  3. Validate remediation through vulnerability scans and log‑based proof of patch deployment.
  4. Document the remediation steps in your vulnerability‑management system to create audit‑ready evidence.
  5. Monitor threat feeds for any new exploitation activity related to these CVEs.

Source: CISA Advisory – KEV Catalog Update (Sept 25 2026)

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →