HomeIntelligenceBrief
VULNERABILITY BRIEF 🟠 High Advisory

CISA Adds Two Actively Exploited MikroTik RouterOS Vulnerabilities (CVE‑2026‑67277, CVE‑2026‑86060) to KEV Catalog

CISA’s KEV Catalog now includes CVE‑2026‑67277 (missing authentication) and CVE‑2026‑86060 (command argument injection) affecting MikroTik RouterOS. The agency urges rapid patching, highlighting the need for robust vulnerability‑management controls to satisfy audit and compliance expectations.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
cisa.gov

Two MikroTik RouterOS Vulnerabilities (CVE‑2026‑67277, CVE‑2026‑86060) Added to CISA KEV Catalog – Active Exploitation Risks

What It Is — CISA announced that two MikroTik RouterOS flaws—a missing‑authentication vulnerability (CVE‑2026‑67277) and an argument‑delimiter injection (CVE‑2026‑86060)—are being actively exploited in the wild and have been added to the Known Exploited Vulnerabilities (KEV) Catalog.

Exploitability — Both vulnerabilities have confirmed exploitation evidence; no public proof‑of‑concept is required. CVSS scores are not yet published but are considered high‑risk due to total control of the device post‑exploitation.

Affected Products — MikroTik RouterOS (all versions vulnerable to the two CVEs).

Why It Matters for Trust & Control Assurance

  • Demonstrates the criticality of a continuous vulnerability‑management program that can surface high‑risk flaws quickly.
  • Provides a concrete control‑evidence point for audit readiness: documented detection, risk‑based prioritization, and remediation of KEV items.
  • Aligns with BOD 26‑04 expectations for federal agencies and serves as a benchmark for private‑sector risk‑based patching policies.

Recommended Actions

  1. Inventory every MikroTik RouterOS instance on public‑facing networks.
  2. Verify current firmware versions against the vendor’s advisory and apply the patches immediately.
  3. Record remediation steps in your vulnerability‑management system to create defensible audit evidence.

Source: CISA Advisory – 2026‑09‑10

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →