CISA KEV Alert 25 Sept 2026, 16:01 UTC

Actively Exploited MikroTik RouterOS Flaw Enables Unauthenticated Attacks

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities (KEV) catalogue on 25 September 2026. The vulnerability affects MikroTik RouterOS and is known as the “Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability”. It allows an unauthenticated client to open a session channel and send an exec request, potentially enabling exploitation of CVE-2026-86060.

The flaw is an improper enforcement of behavioural workflow vulnerability. An unauthenticated attacker can reach the affected RouterOS service remotely, establish a session channel and submit an execution request. The issue can be chained with CVE-2026-86060 to achieve unauthenticated exploitation. NVD assigns it a CVSS score of 6.9, rated Medium. A patch is available, with remediation information published by MikroTik and CERT Polska.

KEV inclusion confirms that attackers are actively exploiting this vulnerability. The available data does not establish known use in ransomware campaigns. CISA set 28 September 2026 as the remediation deadline for affected federal agencies.

CISA requires organisations to apply mitigations in accordance with vendor instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. If mitigations are unavailable, organisations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.

Federal Civilian Executive Branch (FCEB) agencies are directly affected by this requirement, but all organisations should review their RouterOS deployments, internet exposure and patch status.

Consult the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline