CISA's list that day
25 September 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Microsoft SharePoint, MikroTik RouterOS and WordPress Core. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-87902Remote File Inclusion | WordPress Core | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.46 | ||
| CVE-2026-65660Code Injection | Microsoft SharePoint | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| CVE-2026-67279Improper Enforcement of Behavioral Workflow | MikroTik RouterOS | Patch nowListed in the last 14 days | 0.01 |