Vulnerability
CISA Flags Actively Exploited MikroTik RouterOS Vulnerabilities
CISA has expanded its Known Exploited Vulnerabilities catalog with two critical MikroTik RouterOS flaws under active exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding two critical vulnerabilities impacting MikroTik RouterOS devices, adding both to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild.
Understanding the Threats to MikroTik Infrastructure
The two identified flaws, tracked as CVE-2026-67277 and CVE-2026-86060, represent severe risks to enterprise network perimeters. CVE-2026-67277 stems from missing authentication for a critical function, allowing unauthenticated or low-privileged attackers to execute unauthorized actions on affected routers. In parallel, CVE-2026-86060 involves improper neutralization of argument delimiters in command execution, exposing the system to command injection attacks.
Because network routing devices act as gateways to internal infrastructure, threat actors frequently target them to establish footholds, bypass traditional security perimeters, and pivot into internal networks. The active exploitation of these vulnerabilities makes unpatched MikroTik equipment an immediate entry point for advanced persistent threat (APT) groups and criminal syndicates.
Actionable Recommendations and Remediation
Security teams must prioritize identifying and patching all affected MikroTik appliances. First, inventory all perimeter and internal routing equipment to pinpoint exposed RouterOS systems. Second, apply the latest official firmware updates provided by MikroTik immediately to eliminate the vulnerable functions. Third, restrict management interfaces (such as WebFig, WinBox, and SSH) by ensuring they are not publicly reachable from the internet. Organizations should enforce strict access control lists (ACLs) and require multi-factor authentication (MFA) via a secure administrative VPN for all management access.
แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: CISA Cybersecurity Advisories
เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000
บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
