CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-65660 (Microsoft SharePoint Code Injection) and CVE-2026-67279 (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These additions underscore the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies to prioritize remediation of these high-risk vulnerabilities.

IFF Assessment

FOE

The addition of exploited vulnerabilities to CISA's KEV catalog indicates active threats that defenders must address, posing a risk.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 28, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, especially federal agencies, must prioritize patching the newly listed vulnerabilities, CVE-2026-65660 and CVE-2026-67279, as they are actively exploited. This highlights the ongoing need for robust vulnerability management and timely patching to mitigate risks posed by known, weaponized flaws.

Read Full Story →