[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkAYQC8NnMeyrRPwIFaL6DXFXopStlRR7ZbXNwGQFOIM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"ca6acf88-9555-4c96-a45b-785ca197897e","actively-exploited-mikrotik-routeros-flaws-added-to-cisa-kev-catalog","5ba8feed-d46f-4fe3-8c6c-d3c0f0f334f8","Actively Exploited MikroTik RouterOS Flaws Added to CISA KEV Catalog","Two high-severity vulnerabilities in MikroTik RouterOS have been added to CISA's Known Exploited Vulnerabilities Catalog after confirmed active exploitation in the wild. The root issue is a failure to rapidly identify and remediate known vulnerabilities in internet-facing network infrastructure — devices that are particularly high-value targets for attackers seeking persistent access or lateral movement. CISA's Binding Operational Directive mandates timely remediation for federal agencies, but the risk extends to all organizations running unpatched RouterOS devices. Delays in patching widely-used network equipment can expose entire organizational networks to compromise, making proactive vulnerability management essential.","**Immediate actions:**\n- Apply the latest MikroTik RouterOS patches immediately for all affected devices listed under CVE-2026-67277 and CVE-2026-86060.\n- Run an authenticated vulnerability scan across all internet-facing network appliances to identify unpatched instances.\n- Temporarily restrict public-facing access to RouterOS management interfaces until patches are confirmed applied.\n\n**Long-term improvements:**\n- Maintain a continuously updated inventory of all network devices, firmware versions, and patch status using a CMDB or asset management tool.\n- Establish an emergency patching SLA (e.g., 24–72 hours) for any vulnerability added to the CISA KEV Catalog.\n- Implement network segmentation to isolate routing and network infrastructure from user-facing and critical business systems.\n\n**Detection measures:**\n- Subscribe to CISA KEV Catalog alerts and integrate them into your vulnerability management platform for automated prioritization.\n- Enable logging and monitoring on all network appliances to detect anomalous configuration changes or unauthorized access attempts.\n- Deploy intrusion detection signatures specific to known MikroTik exploitation techniques across perimeter and internal monitoring tools.",[12,13,14,15,16,17,18,19],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","CISA BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities","NIST CM-8: System Component Inventory","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","published","2026-09-10T22:21:34.628899+00:00","2026-09-10T22:21:34.333+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F09\u002F10\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-89afc6","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]