Threat Brief — 2026-09-25 — Four CVEs Hit CISA KEV in Single Day
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog today, all confirmed as actively exploited in the wild: Microsoft SharePoint code injection (CVE-2026-65660KEV), MikroTik RouterOS workflow bypass (CVE-2026-67279KEV), WSO2 path traversal (CVE-2026-5430KEV), and Adobe Commerce/Magento authorization bypass (CVE-2026-71362KEV). The SharePoint flaw carries a remediation deadline of 2026-09-28. Separately, two GitHub Actions repositories compromised in the May 2026 Mini Shai-Hulud campaign resumed executing malware after briefly returning online, marking the second time these actions have been disabled.
Top items
- Microsoft SharePoint CVE-2026-65660KEV — now in CISA KEV, remediation due 2026-09-28. An authenticated code injection vulnerability allowing network-based remote code execution. CISA confirms active exploitation and requires remediation within three days. This flaw was first reported on 2026-09-22 when researchers noted it had been misclassified as spoofing despite enabling authenticated RCE. (src: CISA KEV) (src: CISA Alert)
- MikroTik RouterOS CVE-2026-67279KEV — now in CISA KEV. An improper enforcement of behavioral workflow vulnerability allowing unauthenticated clients to open a session channel and send arbitrary commands. Active exploitation confirmed. This continues a story first reported on 2026-09-04 regarding unauthenticated RouterOS takeover chains. (src: CISA KEV) (src: CISA Alert)
- WSO2 Multiple Products CVE-2026-5430KEV — now in CISA KEV. A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway enabling unrestricted file upload leading to remote code execution. Active exploitation confirmed. This was first reported on 2026-09-16 when exploitation attempts were initially observed. (src: CISA KEV) (src: BleepingComputer)
- Adobe Commerce and Magento CVE-2026-71362KEV — now in CISA KEV. An incorrect authorization vulnerability allowing attackers to gain elevated access to sensitive data. Active exploitation confirmed. Also first reported on 2026-09-16 as part of the broader KEV additions covering enterprise software flaws. (src: CISA KEV)
- Compromised GitHub Actions resume malware distribution. Two actions-cool GitHub Actions repositories—previously compromised in the May 2026 Mini Shai-Hulud campaign—became accessible again last week and resumed executing malware before being disabled for a second time. This is a genuine escalation: the same supply-chain compromise vector reactivated despite prior takedown. First reported 2026-09-16. (src: The Hacker News)
Themes
KEV catalog pressure accelerates. Four CVEs added in a single day across diverse product categories—collaboration platforms, network appliances, API gateways, and e-commerce—signals broad opportunistic exploitation rather than a single campaign. The SharePoint remediation deadline (2026-09-28) is the most urgent of the set.
Supply-chain re-infection risk. The GitHub Actions resurgence demonstrates that disabling compromised CI/CD components is not durable—attackers can re-enable repositories and resume malware delivery without new intrusion effort. Organizations relying on third-party Actions should verify they are not consuming the affected actions-cool repositories.
