Cyber ·
CISA Adds Two Cyber Vulnerabilities to Known Exploited Catalog
CISA's new vulnerabilities raise concerns about x-risk from cyber threats targeting federal systems.
Recent actions by the Cybersecurity and Infrastructure Security Agency (CISA) have highlighted two newly identified vulnerabilities that are actively being exploited: CVE-2026-65660, a Microsoft SharePoint code injection vulnerability, and CVE-2026-67279, an improper enforcement vulnerability in Mikrotik RouterOS. These vulnerabilities have been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, which is critical for managing cybersecurity risks, especially within federal agencies.
What the Signal Actually Is
CISA's update on September 25, 2026, indicates that these vulnerabilities are not theoretical but are currently being exploited by malicious actors. The KEV Catalog serves as a resource for identifying vulnerabilities that pose significant risks, particularly those that could grant attackers total control over compromised systems. The Binding Operational Directive (BOD) 26-04 emphasizes the need for Federal Civilian Executive Branch (FCEB) agencies to prioritize the rapid remediation of these high-risk vulnerabilities, particularly on publicly exposed assets. This directive also mandates that agencies assess whether systems were compromised before applying patches.
Why It Matters for Human Extinction Risk Specifically
The potential for exploitation of critical vulnerabilities like those identified by CISA poses an existential risk, particularly if attackers gain access to essential infrastructure. Cyber threats have the capacity to disrupt not only governmental functions but also critical services that societies depend on, such as energy, healthcare, and communication systems. A successful large-scale cyberattack could lead to chaos, undermining societal stability and potentially escalating into broader conflicts. The vulnerabilities in question are indicative of a larger trend where cyber threats are evolving, becoming more sophisticated and targeted, thus increasing the risk to human survival.
Our Take
While CISA's proactive measures in identifying and cataloging these vulnerabilities are commendable, the reality remains that cyber vulnerabilities are often exploited faster than they can be patched. The rapid evolution of cyber threats necessitates continuous vigilance and robust cybersecurity practices across all sectors, not just federal agencies. Organizations, regardless of size, must adopt a risk-based approach to vulnerability management, prioritizing the remediation of known vulnerabilities. The implications of failing to address these vulnerabilities could extend beyond financial loss or data breaches, potentially leading to scenarios that threaten human existence. Therefore, while the situation is serious, it is crucial for stakeholders to remain focused on proactive measures rather than succumbing to alarmism.
*Source: CISA