[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS0t_8kaystty7hAkqu8QBxHM5PypsfDKCZehfmQPY7o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"b529aa01-b223-4d39-aab6-6853c78f6791","cisa-flags-actively-exploited-sharepoint-and-mikrotik-flaws-patch-now","0f23608f-b5e9-45df-a989-e14b0e8e2de9","CISA Flags Actively Exploited SharePoint and MikroTik Flaws — Patch Now","CISA's addition of CVE-2026-65660 (Microsoft SharePoint) and CVE-2026-67279 (MikroTik RouterOS) to the Known Exploited Vulnerabilities catalog confirms that threat actors are actively leveraging these flaws in the wild. The root cause is a failure to apply timely patches to internet-facing systems, leaving critical infrastructure exposed to known, documented attack vectors. Federal agencies are legally bound under BOD 26-04 to remediate KEV-listed vulnerabilities on a mandated timeline, but the real risk extends to any organization running these products. Delayed patching of publicly exposed assets — especially network appliances and collaboration platforms — dramatically increases the attack surface and likelihood of compromise. This incident underscores that vulnerability management must be treated as a continuous, prioritized process rather than a periodic task.","**Immediate actions:**\n- Apply vendor-released patches for CVE-2026-65660 (SharePoint) and CVE-2026-67279 (MikroTik RouterOS) immediately across all affected systems.\n- Run an authenticated vulnerability scan against all internet-facing assets to identify any additional unpatched exposures.\n- Temporarily restrict or isolate affected SharePoint and MikroTik devices from public-facing networks until patches are confirmed applied.\n\n**Long-term improvements:**\n- Establish a formal emergency patching SLA (e.g., 24–72 hours) for vulnerabilities appearing on the CISA KEV catalog.\n- Maintain a continuously updated, authoritative inventory of all internet-exposed assets, including firmware versions on network appliances.\n- Implement network segmentation to limit lateral movement potential from compromised SharePoint servers or edge routers.\n\n**Detection measures:**\n- Configure SIEM alerting to trigger on exploitation indicators associated with new KEV catalog entries within 24 hours of publication.\n- Enable detailed logging on SharePoint access events and MikroTik router traffic to detect anomalous activity indicative of exploitation.\n- Subscribe to CISA KEV catalog feeds and vendor security advisories to ensure zero-delay notification of newly cataloged vulnerabilities.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","CISA BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities","NIST CM-8: System Component Inventory","ISO\u002FIEC 27001:2022 — A.8.8: Management of Technical Vulnerabilities","ITIL 4: Change Enablement Practice (emergency change procedures)","published","2026-09-25T20:22:49.807305+00:00","2026-09-25T20:22:49.507+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F09\u002F25\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-243224","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]