U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

2026-09-26T02:51:38Z•ad28d40e31c6be46d5366533537cb082b5f57e88131ad5f33c5631d344565638
CVE-2026-5430CVE-2026-65660CVE-2026-85102AI-assisted malwareAdobeArista VeloCloud OrchestratorCARBONATOCISA KEVCheck PointClickFixDocker securityF5 BIG-IP APMMicrosoft SharePointMikroTik RouterOSNorth Korea-linked threat actorsPsychedelic StealerRyukWSO2active exploitationcredential theftcryptocurrency theftgovernment portal breachransomwaresupply chain compromise

What happened

SecurityAffairs RSS items report active exploitation and significant cybersecurity incidents, including CISA KEV additions affecting Microsoft SharePoint, MikroTik RouterOS, WSO2, Adobe, Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM. Other reports cover a $351.6 million cryptocurrency theft attributed to suspected North Korea-linked actors, ClickFix delivery of Psychedelic Stealer, the CARBONATO Docker botnet, AI-assisted malware, and unauthorized access to an Australian government health portal. Overall, the collection indicates high-priority exploitation, credential theft, AI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
ad28d40e31c6be46d5366533537cb082b5f57e88131ad5f33c5631d344565638
Enrichment time
2026-09-26T02:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.