highOther

CISA KEV Catalog Addition: MikroTik RouterOS Actively Exploited Vulnerabilities

First seen Sep 11, 2026 · Updated Sep 11, 2026

CISAKEVMikroTikRouterOSnetwork-deviceedge-deviceauthentication-bypasscommand-injectionfederal-mandate

CISA has added two actively exploited MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog: a missing authentication flaw for a critical function and a command argument injection issue. Federal agencies must remediate under BOD 26-04, and CISA urges all organizations to prioritize patching given confirmed in-the-wild exploitation.

Technical Analysis

CVE-2026-67277 involves missing authentication for a critical function in MikroTik RouterOS, allowing unauthenticated attackers to invoke sensitive router functionality remotely. CVE-2026-86060 is an improper neutralization of argument delimiters in a command, indicating a command injection vector likely enabling arbitrary command execution on the router's underlying OS. Both vulnerabilities have confirmed active exploitation, making internet-exposed RouterOS devices high-value targets for initial access, botnet recruitment, or network pivoting. Organizations running AI agent infrastructure, RAG pipelines, or agentic tooling behind MikroTik edge routers or VPN gateways face risk of network compromise that could expose API keys, model endpoints, or internal agent-to-agent traffic if these devices are breached and used for traffic interception or lateral movement into agent-hosting environments.

Affected Systems

MikroTik RouterOS devices with publicly exposed management interfaces or affected services; specific vulnerable versions not detailed in the advisory but confirmed to be in active exploitation per CISA KEV listing

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source advisory; refer to CISA KEV Catalog entry for CVE-2026-67277 and CVE-2026-86060 for technical indicators as they become available

Remediation Steps

  1. 1

    Apply Vendor Patches

    Update all MikroTik RouterOS devices to the latest patched firmware version addressing CVE-2026-67277 and CVE-2026-86060 immediately.

  2. 2

    Restrict Exposure

    Remove RouterOS management interfaces (WinBox, API, web admin) from direct internet exposure; restrict access via VPN or firewall allow-lists.

  3. 3

    Comply with BOD 26-04

    FCEB agencies must remediate per CISA's Binding Operational Directive 26-04 timelines and check for pre-patch compromise indicators.

  4. 4

    Audit for Compromise

    Review router logs, configuration changes, and firmware integrity for signs of prior exploitation before and after patching.

  5. 5

    Segment Critical Infrastructure

    Ensure network segmentation so that compromised edge routers cannot pivot into environments hosting AI agents, credential stores, or sensitive APIs.

CVE / Advisory IDs

CVE-2026-67277CVE-2026-86060

Industries Most Exposed

GovernmentFederal Civilian Executive BranchTelecommunicationsCritical InfrastructureManaged Service ProvidersAny organization using MikroTik networking equipment

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.