CISA added a Microsoft SharePoint flaw and a separate MikroTik RouterOS flaw to its Known Exploited Vulnerabilities catalog on Friday, confirming active exploitation of a bug CyberTech had already flagged as more dangerous than Microsoft’s own advisory suggested.
What happened
Per CISA’s alert, the agency added CVE-2026-65660, a code injection vulnerability in Microsoft Office SharePoint, and CVE-2026-67279, a MikroTik RouterOS flaw involving improper enforcement of a behavioral workflow, to the KEV catalog on September 25. CyberTech reported on CVE-2026-65660 earlier this month, when Microsoft’s own advisory rated it 6.5 as a spoofing issue while Microsoft’s CVE record separately rated the same flaw 8.8 as remote code execution. CISA’s KEV listing settles that discrepancy in favor of the higher rating: the flaw is confirmed exploited in the wild. CISA’s alert states plainly that “these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.”
Why it matters
Federal civilian agencies must remediate KEV-listed flaws on a binding deadline, and the catalog is widely used as a de facto exploitation signal by private-sector security teams too. This is the third distinct MikroTik RouterOS vulnerability added to KEV in roughly a month, following two others CyberTech has already covered, making RouterOS a recurring target rather than a one-off.
The insight
The SharePoint case is the more instructive one: it shows a vendor’s own severity rating can undercount a flaw’s real risk, and it took confirmed in-the-wild exploitation, not a re-review of the advisory, to correct the record. Security teams that triage patches by vendor CVSS score alone would have deprioritized this bug for weeks. The KEV catalog is a lagging confirmation of exploitation already underway, a pattern CyberTech’s reporting on federal patch-adoption gaps has tracked repeatedly this month, and it should not be mistaken for an early warning system. Patch SharePoint and RouterOS now if unpatched, and treat any advisory-versus-CVE-record mismatch as reason to assume the worse rating until proven otherwise.
Source: CISA