Code Injection in Microsoft SharePoint (CVE‑2026‑65660) and SSH Bypass in MikroTik RouterOS (CVE‑2026‑67279) Added to CISA KEV Catalog
What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed two high‑severity flaws into its Known Exploited Vulnerabilities (KEV) catalog: a remote code‑injection issue in Microsoft SharePoint Server (CVE‑2026‑65660, CVSS 8.8) and an unauthenticated SSH‑bypass in MikroTik RouterOS (CVE‑2026‑67279, CVSS 6.9).
Exploitability – Both vulnerabilities are confirmed to be actively exploited in the wild. The SharePoint flaw requires a low‑privileged authenticated user, while the RouterOS bug can be leveraged without credentials and has been chained with CVE‑2026‑86060 to obtain full admin access.
Affected Products – Microsoft SharePoint Server 2016, 2019, and Subscription Edition; MikroTik RouterOS (all supported versions).
Why It Matters for Trust & Control Assurance
- Continuous vulnerability monitoring is a core control objective; the KEV listing signals that failure to remediate is a measurable risk gap across most frameworks.
- Demonstrable evidence of patching or mitigation satisfies auditors looking for “defensible” remediation trails.
- Federal directive BOD 22‑01 forces agencies to close the gap by 28 Sept 2026, and private firms are urged to follow suit to maintain a trustworthy security posture.
Recommended Actions
- Prioritize patching SharePoint Server and updating RouterOS to the vendor‑released fixes.
- Run authenticated scans (e.g., credentialed Nessus, Qualys) to confirm remediation.
- Capture remediation tickets, patch‑install logs, and scan results as evidence for your control‑mapping repository.
- Align the remediation effort with the “Vulnerability Management” control area in your chosen framework (e.g., NIST CSF ID.RA‑1).
Source: SecurityAffairs article