rootpwn

Advisories

CISA Expands KEV Catalog with Two New MikroTik RouterOS Exploits

CISA has added two actively exploited vulnerabilities that target MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. CVE‑2026‑67277 allows attackers to bypass authentication for a critical function, while CVE‑2026‑86060 lets them inject malicious commands by exploiting improper argument neutralization. The update reinforces federal guidance under BOD 26‑04 to prioritize rapid patching of high‑risk flaws on publicly exposed assets, and invites all organizations to adopt a risk‑based approach to remediation.

In a recent update, the Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) catalog to include two new CVEs that have been actively abused in the wild. Both flaws affect MikroTik RouterOS, a popular firmware used in many network devices worldwide.

Vulnerabilities Added

  • CVE‑2026‑67277 – Missing authentication for a critical function that can give attackers full control over the device.
  • CVE‑2026‑86060 – Improper neutralization of argument delimiters in a command, enabling injection of arbitrary commands.

These weaknesses are especially dangerous because they allow remote attackers to gain unrestricted access to exposed MikroTik routers, a common target for botnet and ransomware operations.

Implications for Federal Agencies

Under Binding Operational Directive (BOD) 26‑04, federal civilian executive branch agencies must prioritize remediation of KEV-listed CVEs on publicly exposed assets that could grant total control to an attacker. The directive also requires agencies to verify whether a system has been compromised before applying a patch.

"CISA will continue to add vulnerabilities that meet the exploitation criteria to the KEV catalog," a CISA spokesperson said. "We encourage all organizations to adopt a risk‑based approach and focus on these high‑risk flaws first."

What You Can Do

  • Check whether your MikroTik devices are running affected firmware versions and apply the latest patch immediately.
  • Audit exposed network equipment for signs of compromise before updating.
  • Submit any other known exploited vulnerabilities to CISA via the KEV Nomination Form if they meet the criteria (CVE ID, evidence of exploitation, and clear mitigation).

While BOD 26‑04 applies to federal agencies, CISA’s guidance is a useful benchmark for any organization that wants to strengthen its vulnerability management program.

CISA KEV MikroTik RouterOS Vulnerability Patch Federal

← All news