Actively Exploited MikroTik RouterOS Flaws Added to CISA KEV Catalog
Two high-severity vulnerabilities in MikroTik RouterOS have been added to CISA's Known Exploited Vulnerabilities Catalog after confirmed active exploitation in the wild. The root issue is a failure to rapidly identify and remediate known vulnerabilities in internet-facing network infrastructure — devices that are particularly high-value targets for attackers seeking persistent access or lateral movement. CISA's Binding Operational Directive mandates timely remediation for federal agencies, but the risk extends to all organizations running unpatched RouterOS devices. Delays in patching widely-used network equipment can expose entire organizational networks to compromise, making proactive vulnerability management essential.
Tactical Insight
Immediate actions
- Apply the latest MikroTik RouterOS patches immediately for all affected devices listed under CVE-2026-67277 and CVE-2026-86060.
- Run an authenticated vulnerability scan across all internet-facing network appliances to identify unpatched instances.
- Temporarily restrict public-facing access to RouterOS management interfaces until patches are confirmed applied.
Long-term improvements
- Maintain a continuously updated inventory of all network devices, firmware versions, and patch status using a CMDB or asset management tool.
- Establish an emergency patching SLA (e.g., 24–72 hours) for any vulnerability added to the CISA KEV Catalog.
- Implement network segmentation to isolate routing and network infrastructure from user-facing and critical business systems.
Detection measures
- Subscribe to CISA KEV Catalog alerts and integrate them into your vulnerability management platform for automated prioritization.
- Enable logging and monitoring on all network appliances to detect anomalous configuration changes or unauthorized access attempts.
- Deploy intrusion detection signatures specific to known MikroTik exploitation techniques across perimeter and internal monitoring tools.