# CISA flags active exploits in SharePoint, RouterOS

Published: 2026-09-25 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/3c98fe2a-f3ed-5ac8-8b07-490c9a32c6b9/cisa-flags-active-exploits-in-sharepoint-routeros

> CISA added actively exploited SharePoint code injection and Mikrotik RouterOS flaws to its KEV catalog, requiring federal remediation.

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, and CVE-2026-67279, an improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS. Both entries indicate that threat actors are actively leveraging these flaws in the wild, making them priority targets for patching.

Under Binding Operational Directive (BOD) 26-04, FCEB agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that grant full post-exploitation control, and must check for prior compromise before patching. While the directive is binding only on federal civilian agencies, CISA recommends all organizations running affected SharePoint or RouterOS deployments treat these as high-priority patches and review systems for signs of compromise predating remediation.

No technical details of the exploitation chains, IOCs, or attributed threat actors were provided in this bulletin; defenders should consult vendor advisories from Microsoft and Mikrotik for patch details and check exposure of internet-facing SharePoint servers and RouterOS devices.

## Mentioned in this report

- Vulnerabilities: CVE-2026-65660 (KEV), CVE-2026-67279 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3c98fe2a-f3ed-5ac8-8b07-490c9a32c6b9/cisa-flags-active-exploits-in-sharepoint-routeros.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
