CISA adds Microsoft SharePoint and MikroTik RouterOS flaws to KEV catalog
CISA added a Microsoft SharePoint code-injection flaw (CVE-2026-65660, CVSS 8.8) and a MikroTik RouterOS SSH authentication bypass (CVE-2026-67279, CVSS 6.9) to its Known Exploited Vulnerabilities catalog. Both are actively exploited, and U.S. federal agencies must patch by September 28, 2026.
- CVE-2026-65660 affects SharePoint Server 2016, 2019 and Subscription Edition, CVSS 8.8
- CVE-2026-67279 lets unauthenticated attackers bypass RouterOS authentication, CVSS 6.9
- CERT Polska confirmed RouterOS attacks dating back to September 2, 2026
- Federal agencies must remediate the flaws by September 28, 2026
Read next
Security