← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 21:03via Security Affairs

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :

  • CVE-2026-65660 (CVSS score of 8.8) Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary code remotely. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition.

The second flaw added to the catalog, tracked as CVE-2026-67279 (CVSS score of 6.

Read more on Security Affairs→