Advisories
CISA Expands KEV Catalog with Two New MikroTik RouterOS Vulnerabilities
CISA has added CVE‑2026‑67277 and CVE‑2026‑86060 to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaws let attackers bypass authentication and inject malicious commands on MikroTik RouterOS devices, giving full control. Federal agencies are urged to patch immediately under BOD 26‑04, which prioritizes remediation of high‑risk KEVs on publicly exposed assets. All organizations are encouraged to adopt a risk‑based approach and can submit new KEVs for consideration via CISA’s nomination form.
In a move that tightens the federal security posture, CISA has broadened its Known Exploited Vulnerabilities (KEV) catalog by adding two new MikroTik RouterOS flaws. Both vulnerabilities—CVE‑2026‑67277 (missing authentication for a critical function) and CVE‑2026‑86060 (improper neutralization of argument delimiters)—have been proven in the wild and can grant attackers full control of affected routers.
What the Additions Mean for Federal Agencies
- Under Binding Operational Directive 26‑04, federal civilian executive branch (FCEB) agencies must prioritize rapid patching of KEVs that expose publicly reachable assets.
- The directive stresses that agencies check for compromise before applying a fix and defer lower‑risk vulnerabilities.
- While the mandate applies to FCEB, CISA urges all organizations to follow a risk‑based remediation strategy.
Next Steps for All Organizations
- Verify if your MikroTik devices are running vulnerable RouterOS versions.
- Apply the latest security updates immediately.
- Monitor for signs of exploitation and conduct post‑patch vulnerability scans.
- Consider submitting other actively exploited CVEs to the KEV catalog via CISA’s nomination form.
“CISA will continue to add vulnerabilities that meet the criteria of active exploitation, a CVE ID, and clear mitigation guidance,” the agency noted.