CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on 25 September 2026, citing evidence that both are being actively exploited. The entries are CVE-2026-65660, a Microsoft SharePoint code injection vulnerability, and CVE-2026-67279, a MikroTik RouterOS improper enforcement of behavioural workflow vulnerability. CISA said vulnerabilities in the catalogue are frequently used by malicious cyber actors and pose significant risks to federal systems.
The update is covered by Binding Operational Directive (BOD) 26-04, which requires US Federal Civilian Executive Branch agencies to prioritise rapid remediation of KEV vulnerabilities on publicly exposed assets that provide total control after exploitation. The directive also sets expectations for checking whether systems were compromised before patches were applied, although it applies only to those federal agencies.
CISA encouraged all organisations to use risk-based vulnerability management and prioritise the two newly listed vulnerabilities, but the notice did not provide affected product versions, technical exploitation details, or specific patch deadlines.