CISA flags active exploits in SharePoint, RouterOS
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CISA added actively exploited SharePoint code injection and Mikrotik RouterOS flaws to its KEV catalog, requiring federal remediation.
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, and CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS. Both entries indicate that threat actors are actively leveraging these flaws in the wild, making them priority targets for patching.
Under Binding Operational Directive (BOD) 26-04, FCEB agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that grant full post-exploitation control, and must check for prior compromise before patching. While the directive is binding only on federal civilian agencies, CISA recommends all organizations running affected SharePoint or RouterOS deployments treat these as high-priority patches and review systems for signs of compromise predating remediation.
No technical details of the exploitation chains, IOCs, or attributed threat actors were provided in this bulletin; defenders should consult vendor advisories from Microsoft and Mikrotik for patch details and check exposure of internet-facing SharePoint servers and RouterOS devices.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,162 reports from 155 sources, 1,790 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs