Two MikroTik RouterOS Vulnerabilities (CVE‑2026‑67277, CVE‑2026‑86060) Added to CISA KEV Catalog – Active Exploitation Risks
What It Is — CISA announced that two MikroTik RouterOS flaws—a missing‑authentication vulnerability (CVE‑2026‑67277) and an argument‑delimiter injection (CVE‑2026‑86060)—are being actively exploited in the wild and have been added to the Known Exploited Vulnerabilities (KEV) Catalog.
Exploitability — Both vulnerabilities have confirmed exploitation evidence; no public proof‑of‑concept is required. CVSS scores are not yet published but are considered high‑risk due to total control of the device post‑exploitation.
Affected Products — MikroTik RouterOS (all versions vulnerable to the two CVEs).
Why It Matters for Trust & Control Assurance
- Demonstrates the criticality of a continuous vulnerability‑management program that can surface high‑risk flaws quickly.
- Provides a concrete control‑evidence point for audit readiness: documented detection, risk‑based prioritization, and remediation of KEV items.
- Aligns with BOD 26‑04 expectations for federal agencies and serves as a benchmark for private‑sector risk‑based patching policies.
Recommended Actions
- Inventory every MikroTik RouterOS instance on public‑facing networks.
- Verify current firmware versions against the vendor’s advisory and apply the patches immediately.
- Record remediation steps in your vulnerability‑management system to create defensible audit evidence.
Source: CISA Advisory – 2026‑09‑10