CISA's list that day

25 September 2026

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Microsoft SharePoint, MikroTik RouterOS and WordPress Core. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-87902Remote File InclusionWordPress CorePatch nowForensic triage required by CISA; listed in the last 14 days0.46
CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
CVE-2026-67279Improper Enforcement of Behavioral WorkflowMikroTik RouterOSPatch nowListed in the last 14 days0.01