The U.S. Cybersecurity and Infrastructure Security Agency added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, including flaws in Microsoft SharePoint, MikroTik RouterOS, WordPress, and WSO2 software. All are confirmed to be under active exploitation.
7 reportsother · primary
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
CISA updated its Known Exploited Vulnerabilities catalog on Sept. 25, adding actively exploited flaws affecting WSO2, Adobe Commerce and Magento, Microsoft SharePoint, and MikroTik RouterOS [cisa.gov#1][thehackernews.com#1][bleepingcomputer.com#1]. The issues include a WSO2 authentication bypass, an Adobe authorization flaw, SharePoint code injection, and a MikroTik RouterOS workflow-enforcement v
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Securit
🚨 [CISA-2026:0925] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0925 ) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199777/hac king/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html