Two entries backed by exploitation evidence
CISA added CVE-2026-65660, a Microsoft SharePoint code-injection vulnerability, and CVE-2026-67279, a MikroTik RouterOS workflow-enforcement vulnerability, to its Known Exploited Vulnerabilities catalog on September 25. The agency says inclusion is based on evidence of active exploitation. That makes these entries more than a list of theoretical weaknesses, but it does not establish that a particular business has been compromised.
Start with an answer about exposure
A useful response begins with an accountable inventory check. Our recommendation is for the owner of each named product to establish whether it is deployed, which versions and configurations are present and which official remediation instructions apply. A retailer should include the team or provider responsible for network equipment at its locations. A telecommunications business should distinguish customer-managed equipment from infrastructure it operates itself. These are scoping questions, not assertions that all deployments or devices from either vendor are vulnerable.
Keep deadlines and evidence in their proper scope
CISA’s notice explains that its federal vulnerability-management directive applies to Federal Civilian Executive Branch agencies and encourages other organizations to prioritize catalog entries through risk-based management. Businesses should not copy a federal obligation into a customer notice as if it automatically binds every private organization. Equally, an exploited listing should not disappear into an ordinary backlog without an exposure decision. The actual response should follow the current vendor instructions and the organization’s verified environment.
Close the loop with the service provider
For a small business using an MSP, the most useful request is a written status: affected, not affected or still being assessed, with the supporting product information and next action. If work is required, ask who owns the change, how it will be verified and whether incident investigation is also warranted. A patch completion notice and a finding about prior compromise answer different questions. Recording both prevents a maintenance task from being mistaken for a complete assessment of what happened before the fix.
Sources & further reading
Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.
