CISA Adds Two MikroTik RouterOS Flaws to KEV
CISA added two actively exploited MikroTik RouterOS vulnerabilities to its KEV catalog, requiring urgent remediation by federal agencies.
CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. CVE-2026-67277 is a missing authentication vulnerability affecting a critical function, and CVE-2026-86060 involves improper neutralization of argument delimiters in a command, which could enable command injection. Both affect MikroTik RouterOS, a widely deployed network operating system used in routers and networking equipment across enterprise, ISP, and small-office environments, making it an attractive target for threat actors seeking to compromise network infrastructure.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of vulnerabilities in the KEV Catalog, particularly those on publicly exposed assets that could grant an attacker total control post-exploitation. The directive also requires agencies to check whether systems were compromised prior to patching. While BOD 26-04 only binds FCEB agencies, CISA recommends all organizations using MikroTik RouterOS treat these as high-priority patches given confirmed in-the-wild exploitation.
Defenders operating MikroTik RouterOS devices, especially those exposed to the internet, should identify affected versions, apply vendor patches or mitigations immediately, and audit devices for signs of compromise predating remediation. Given RouterOS devices are frequently used as edge/perimeter network equipment, compromise could enable persistent network access, traffic interception, or use as a pivot point for further intrusion.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free