Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the ongoing threat landscape in the cyber world. The Microsoft SharePoint code injection vulnerability and the Mikrotik RouterOS improper enforcement of behavioral workflow vulnerability pose significant concerns for organizations, emphasizing the importance of patching and protecting systems against known exploited vulnerabilities.
The United States Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are the Microsoft SharePoint code injection vulnerability (CVE-2026-65660) and the Mikrotik RouterOS improper enforcement of behavioral workflow vulnerability (CVE-2026-67279). The Microsoft SharePoint vulnerability has a CVSS score of 8.8 and allows an authenticated, low-privileged attacker to execute arbitrary code remotely. The Mikrotik RouterOS vulnerability has a CVSS score of 6.9 and allows an unauthenticated attacker to bypass normal authentication and execute commands. CISA advises federal agencies and private organizations to address these vulnerabilities by September 28, 2026, to protect their networks against attacks.
The United States Cybersecurity and Infrastructure Security Agency (CISA) has recently added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, marking an important development in the ongoing efforts to protect against cyber threats. The two vulnerabilities in question are the Microsoft SharePoint code injection vulnerability (CVE-2026-65660) and the Mikrotik RouterOS improper enforcement of behavioral workflow vulnerability (CVE-2026-67279).
The Microsoft SharePoint code injection vulnerability, with a CVSS score of 8.8, is a critical flaw that allows an authenticated, low-privileged attacker to execute arbitrary code remotely. This vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition, making it essential for organizations to take immediate action to patch and protect their systems. The fact that this vulnerability has been actively exploited in the wild, with CERT Polska confirming that it can lead to full administrative access without authentication, highlights the severity of the threat.
The Mikrotik RouterOS improper enforcement of behavioral workflow vulnerability, with a CVSS score of 6.9, is another significant concern. This vulnerability allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel, and execute commands, potentially creating or modifying files on the device. CERT Polska has reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain. This vulnerability has also been actively exploited, and its chaining with CVE-2026-86060 can lead to full administrative access without authentication.
The addition of these vulnerabilities to the KEV catalog serves as a reminder of the importance of staying vigilant and proactive in the face of emerging cyber threats. CISA's efforts to identify and prioritize vulnerabilities like these are crucial in helping organizations stay ahead of the threats and protect their networks. It is essential for federal agencies to address these vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Private organizations are also advised to review the KEV catalog and address the vulnerabilities in their infrastructure to minimize the risk of exploitation. The fact that CISA orders federal agencies to fix the flaws by September 28, 2026, emphasizes the urgency of this situation.
The recent addition of these vulnerabilities to the KEV catalog highlights the need for continued vigilance and proactive measures in the fight against cyber threats. It is crucial for organizations to stay informed and take immediate action to patch and protect their systems against these known exploited vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Microsoft-SharePoint-and-Mikrotik-RouterOS-Flaws-to-its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml
https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-65660
https://www.cvedetails.com/cve/CVE-2026-65660/
https://nvd.nist.gov/vuln/detail/CVE-2026-67279
https://www.cvedetails.com/cve/CVE-2026-67279/
https://nvd.nist.gov/vuln/detail/CVE-2026-86060
https://www.cvedetails.com/cve/CVE-2026-86060/
Published: Fri Sep 25 16:36:27 2026 by llama3.2 3B Q4_K_M