CISA KEV Catalog Addition: MikroTik RouterOS Actively Exploited Vulnerabilities
First seen Sep 11, 2026 · Updated Sep 11, 2026
CISA has added two actively exploited MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog: a missing authentication flaw for a critical function and a command argument injection issue. Federal agencies must remediate under BOD 26-04, and CISA urges all organizations to prioritize patching given confirmed in-the-wild exploitation.
Technical Analysis
CVE-2026-67277 involves missing authentication for a critical function in MikroTik RouterOS, allowing unauthenticated attackers to invoke sensitive router functionality remotely. CVE-2026-86060 is an improper neutralization of argument delimiters in a command, indicating a command injection vector likely enabling arbitrary command execution on the router's underlying OS. Both vulnerabilities have confirmed active exploitation, making internet-exposed RouterOS devices high-value targets for initial access, botnet recruitment, or network pivoting. Organizations running AI agent infrastructure, RAG pipelines, or agentic tooling behind MikroTik edge routers or VPN gateways face risk of network compromise that could expose API keys, model endpoints, or internal agent-to-agent traffic if these devices are breached and used for traffic interception or lateral movement into agent-hosting environments.
Affected Systems
MikroTik RouterOS devices with publicly exposed management interfaces or affected services; specific vulnerable versions not detailed in the advisory but confirmed to be in active exploitation per CISA KEV listing
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source advisory; refer to CISA KEV Catalog entry for CVE-2026-67277 and CVE-2026-86060 for technical indicators as they become available
Remediation Steps
- 1
Apply Vendor Patches
Update all MikroTik RouterOS devices to the latest patched firmware version addressing CVE-2026-67277 and CVE-2026-86060 immediately.
- 2
Restrict Exposure
Remove RouterOS management interfaces (WinBox, API, web admin) from direct internet exposure; restrict access via VPN or firewall allow-lists.
- 3
Comply with BOD 26-04
FCEB agencies must remediate per CISA's Binding Operational Directive 26-04 timelines and check for pre-patch compromise indicators.
- 4
Audit for Compromise
Review router logs, configuration changes, and firmware integrity for signs of prior exploitation before and after patching.
- 5
Segment Critical Infrastructure
Ensure network segmentation so that compromised edge routers cannot pivot into environments hosting AI agents, credential stores, or sensitive APIs.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.