Cyber Security News

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild.

On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations.

MikroTik RouterOS Flaws

CVE-2026-67277 is a missing-authentication vulnerability in the bandwidth-test service (btest) of MikroTik RouterOS. Classified under CWE-306, this issue could allow an attacker to disclose kernel memory and trigger a denial-of-service condition.

Exposing kernel memory is particularly serious, as leaked data may reveal sensitive information and help attackers bypass security measures during later stages of exploitation.

The second vulnerability, CVE-2026-86060, results from improper neutralization of argument delimiters in a command, tracked as CWE-88. According to the KEV entry, an attacker could manipulate the trusted RouterOS policy mask, potentially enabling privilege escalation.

An attacker who gains elevated permissions on a network router may alter routing rules, create persistence, intercept traffic, or use the device as a pivot point for further internal attacks.

CISA has designated CVE-2026-86060 as requiring forensic triage under Binding Operational Directive 26-04, indicating that affected organizations should investigate for signs of compromise in addition to applying mitigations.

Although CISA’s listing does not mention ransomware for either flaw, both are now classified as actively exploited vulnerabilities, making rapid assessment and remediation essential.

Federal Civilian Executive Branch agencies must adhere to the KEV remediation deadline. At the same time, CISA strongly urges all organizations operating MikroTik RouterOS devices to prioritize addressing these vulnerabilities.

Administrators should identify internet-exposed RouterOS systems, review vendor advisories for fixed releases or mitigations, restrict access to management and btest-service, and check device logs and configuration changes for signs of unauthorized activity.

The short three-day remediation window emphasizes CISA’s assessment that vulnerable RouterOS deployments pose an immediate operational risk. Organizations that cannot implement effective mitigations should consider removing affected devices from exposure until a secure configuration or updated software version is available.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

2 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

3 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

3 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

4 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

4 hours ago

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to…

5 hours ago