การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Vulnerability

CISA Flags Exploited MikroTik RouterOS Flaws in Latest KEV Catalog Update

FORTSECURE GLOBAL· 2026-09-11🛰 CISA Cybersecurity Advisories
#Vulnerability#Network Security#Cyber Risk#CISA

CISA has added two actively exploited MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalog. Administrators are urged to patch immediately.

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding two critical flaws affecting MikroTik RouterOS. The inclusion is driven by concrete evidence that threat actors are actively leveraging these flaws in real-world attacks. These weaknesses provide entry points for remote attackers seeking persistent footholds in enterprise and critical infrastructure network environments.

Overview of the MikroTik Flaws

The two documented vulnerabilities are tracked as CVE-2026-67277 and CVE-2026-86060. The former represents a missing authentication vulnerability within critical management functions, allowing unauthenticated adversaries to execute privileged operations remotely. The latter involves improper neutralization of argument delimiters, enabling command injection where malicious input can alter system commands. Together, these flaws present substantial operational risks, especially for network edge devices frequently exposed to the public internet.

Mitigation and Practical Guidance

Network administrators must prioritize patching affected MikroTik devices without delay:

  • Immediately apply the vendor-provided firmware updates to all active MikroTik RouterOS deployments.
  • Restrict administrative access by disabling management interfaces from WAN connections and enforcing strong network segmentation.
  • Implement multi-factor authentication (MFA) and monitor logs for anomalous administrative logins or configuration alterations.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog