Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-26 · updated: 2026-09-26 · tags: [incident, government] · confidence: high · severity: medium · affected_sectors: [government] · au_impact: false

CISA's 25 September additions to the Known Exploited Vulnerabilities catalog are a high-severity code injection flaw in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine and workflow bypass in MikroTik RouterOS (CVE-2026-67279), both added on evidence of active exploitation. The remediation dates — 28 September — give federal civilian agencies a three-day window, and CISA's alert frames the additions under BOD 26-04, which requires agencies to prioritise flaws on publicly exposed assets that grant total control and to check for pre-patch compromise. The pairing is instructive because severity and urgency have come apart: the MikroTik flaw is rated medium and still carries the same deadline as a high-severity SharePoint code injection, since both are already being used. Organisations outside the federal enterprise are encouraged to apply the same risk-based triage rather than waiting for formal exploitation confirmation.

Attribute Detail
Sector Government
Date 2026-09-26
Source CISA
Reliability Tier 1
CVEs CVE-2026-65660, CVE-2026-67279