CISA Adds Two MikroTik RouterOS Flaws to Known Exploited Vulnerabilities Catalog
CISA added CVE-2026-86060 and CVE-2026-67277 in MikroTik RouterOS to the KEV catalog. MikroTik has released fixed RouterOS versions and recommends restricting SSH access.

MikroTik RouterOS KEV is a new priority for network infrastructure administrators. On September 10, 2026, the U.S. agency CISA added the CVE-2026-86060 and CVE-2026-67277 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, a record of flaws with known active exploitation. The manufacturer has already released fixes for both flaws in selected RouterOS versions.
RouterOS is also used in edge network devices, so organizations should promptly check the system version in use, update it, and verify that management interfaces are not unnecessarily accessible from the internet. MikroTik specifically recommends not exposing SSH to untrusted networks.
MikroTik RouterOS KEV: Two Different Flaws
CVE-2026-86060 concerns argument processing during SSH login in RouterOS. According to the available technical description, it may lead to privilege escalation. The condition is access to an unauthenticated SSH session for the login helper process. CERT Polska places this vulnerability in the group of flaws that MikroTik called MikroTrick.
The second flaw, CVE-2026-67277, enables an unauthenticated kernel memory disclosure and denial of service through the btest service. It is therefore a different type of risk than the SSH flaw: the described impact includes exposing data from kernel memory as well as disrupting device availability.
In the supplied KEV record, CISA lists both CVEs and recommends following the manufacturer’s instructions. Inclusion in KEV is a significant signal for teams that prioritize vulnerability remediation, but details about specific attacks, affected organizations, or the extent of exploitation of either flaw have not been publicly confirmed.
Fixes Are Available in RouterOS 6 and 7
MikroTik released fixes in RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3. Administrators should verify which branch and specific release are running on their devices and deploy the appropriate fixed version according to the manufacturer’s instructions.
Priority should be given especially to devices whose SSH interface or other management access is exposed to the internet. MikroTik’s recommendation not to expose SSH to untrusted networks means that access to this service should be restricted to trusted source networks. However, this restriction does not replace updating RouterOS.
- identify devices running RouterOS and determine their exact version,
- update to the manufacturer-specified fixed release for the branch in use,
- check whether SSH is accessible from untrusted networks,
- prioritize internet-accessible routers and devices with management interfaces.
What Remains Unclear
The Canadian Cyber Centre cites active exploitation of CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060 based on open-source reports. However, these are not independently described forensic cases from that institution. The public materials in the supplied source documents also do not provide indicators of compromise or a technical scenario for specific attacks.
For CVE-2026-67277, there is also a timing discrepancy in older data: the CISA ADP record listed the exploitation status as “none” as of September 8, 2026. However, this data predates the September 10 KEV record, which classified the flaw among known actively exploited vulnerabilities.
Further information may emerge if CISA adds technical details or a remediation deadline to KEV, or if MikroTik or CERT Polska publish details about exploitation and indicators of compromise. Any reports linking CVE-2026-86060 to other flaws in the MikroTrick group will also be important.
Sources
- CISA Known Exploited Vulnerabilities Catalog – The supplied primary record lists CVE-2026-86060 as added to KEV on September 10, 2026, and recommends following the manufacturer’s instructions.
- MikroTik – September 2026 vulnerability – The manufacturer confirms the release of fixes, lists the fixed versions, and recommends restricting SSH to trusted networks.
- CERT Polska – Vulnerabilities in Mikrotik RouterOS software – Provides technical descriptions of CVE-2026-86060 and CVE-2026-67277, affected versions, and fixed releases.
- Canadian Centre for Cyber Security – AV26-887 – States that open-source reports signal exploitation of CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060.
Verified and updated: September 11, 2026 06:23



