In an alert published on September 25, 2026, CISA announced two additions to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation: CVE-2026-65660, a code-injection vulnerability in Microsoft SharePoint, and CVE-2026-67279, involving improper workflow rule enforcement in MikroTik RouterOS.
The agency says these vulnerability classes are frequent attack vectors and pose significant risks to the federal environment. Binding Operational Directive BOD 26-04 sets vulnerability-management requirements for U.S. Federal Civilian Executive Branch (FCEB) agencies.
According to the alert, the directive prioritizes rapid remediation of high-risk KEV vulnerabilities on publicly exposed assets when exploitation grants full control of the asset; action on lower-risk flaws may be deferred. It also sets baseline expectations for checking whether threat actors compromised a system before applying patches. BOD 26-04 applies only to FCEB agencies, but CISA encourages all organizations to adopt risk-based management and prioritize KEV vulnerabilities.
To apply the information, check whether the two CVEs affect your organization’s assets and consult the KEV catalog and vendor advisories to assess exposure and available mitigations. Do not assume that a catalog entry alone describes your configuration or confirms a compromise: assess systems and investigate relevant indicators before and during remediation, following your organization’s process.
To verify the report, consult CISA’s original alert, the KEV catalog, and BOD 26-04; the source text is an automatic translation of CISA feed content. CISA says a proposed KEV entry should have a CVE ID, proof