⌁ DAY 27UNDERCOVERED IN US

CISA flags four actively exploited software vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, including flaws in Microsoft SharePoint, MikroTik RouterOS, WordPress, and WSO2 software. All are confirmed to be under active exploitation.

7 reportsother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CISA flags four exploited software flaws, sets federal deadline

kite:cybersecurityother4d ago kagi ↗

CISA updated its Known Exploited Vulnerabilities catalog on Sept. 25, adding actively exploited flaws affecting WSO2, Adobe Commerce and Magento, Microsoft SharePoint, and MikroTik RouterOS [cisa.gov#1][thehackernews.com#1][bleepingcomputer.com#1]. The issues include a WSO2 authentication bypass, an Adobe authorization flaw, SharePoint code injection, and a MikroTik RouterOS workflow-enforcement v

CISA Adds Two Known Exploited Vulnerabilities to Catalog

rss:cisa-advisoriesprimary4d ago kagi ↗

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant

CISA Adds One Known Exploited Vulnerability to Catalog

rss:cisa-advisoriesprimary4d ago kagi ↗

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securit

https://www. cisa.gov/news-events/alerts/20 26/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik Rout

mastodon:infosec-exchangeother4d ago kagi ↗

https://www. cisa.gov/news-events/alerts/20 26/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0925 ) CISA has added 2 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother4d ago kagi ↗

🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0925 ) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

CISA has updated the catalogue. - CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability https://www. cisa.gov/known-exploited-vulne rabilities-catalog?search_api_fulltext=&field_date_added

mastodon:infosec-exchangeother4d ago kagi ↗

CISA has updated the catalogue. - CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability https://www. cisa.gov/known-exploited-vulne rabilities-catalog?search_api_fulltext=&field_date_added_wrapper=all&sort_by=field_date_added&items_per_page=20 - CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability https://www. cve.org/CVERecord?id=CVE-2026- 67279

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199777/hac king/u-s-cisa-adds-microsoft-sharepoint-and-mikro

mastodon:infosec-exchangeother2d ago kagi ↗

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199777/hac king/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html