CISA's 25 September additions to the Known Exploited Vulnerabilities catalog are a high-severity code injection flaw in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine and workflow bypass in MikroTik RouterOS (CVE-2026-67279), both added on evidence of active exploitation. The remediation dates — 28 September — give federal civilian agencies a three-day window, and CISA's alert frames the additions under BOD 26-04, which requires agencies to prioritise flaws on publicly exposed assets that grant total control and to check for pre-patch compromise. The pairing is instructive because severity and urgency have come apart: the MikroTik flaw is rated medium and still carries the same deadline as a high-severity SharePoint code injection, since both are already being used. Organisations outside the federal enterprise are encouraged to apply the same risk-based triage rather than waiting for formal exploitation confirmation.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-26 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-65660, CVE-2026-67279 |