ZeroHour
GBHackerspublished ()ingested Divya1
Part of a story covered by 3 sources: “MikroTik RouterOS flaws actively exploited for full router takeover; CISA adds two to KEV catalog with September 13 deadline” — merged summary and timeline →

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

highExploit / PoC exploited in the wildimportance 78CVE-2026-67277CVE-2026-86060
AI summary · glm-5.3-flash

CISA added two actively exploited MikroTik RouterOS flaws, CVE-2026-67277 and CVE-2026-86060, to its KEV catalog with a September 13 mitigation deadline.

CISA added CVE-2026-67277 and CVE-2026-86060 in MikroTik RouterOS to the Known Exploited Vulnerabilities catalog on September 10, giving federal agencies until September 13 to apply vendor mitigations. CVE-2026-67277 is a missing-authentication flaw (CWE-306) in the bandwidth-test (btest) service that can expose kernel memory and cause denial of service; CVE-2026-86060 (CWE-88) lets attackers manipulate the trusted RouterOS policy mask for privilege escalation. CISA designated CVE-2026-86060 as requiring forensic triage under Binding Operational Directive 26-04, meaning organizations should hunt for compromise indicators, not just patch. Compromised routers could have altered routing rules, persistence, traffic interception, or use as pivots into internal networks.

  • CVE-2026-67277 exposes kernel memory via the unauthenticated btest service
  • CVE-2026-86060 enables RouterOS policy-mask tampering and privilege escalation
  • Federal agencies face a September 13 remediation deadline under KEV rules
  • CISA mandates forensic triage of CVE-2026-86060 for compromise indicators
  • Defenders should restrict btest exposure and review router logs for tampering
ProductsRouterOS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-86060
+1 in the same advisory: …67277
Argument-Injection Flaw in MikroTik RouterOS SSH Login Enables Privilege Escalation

CVE-2026-86060 is an argument-injection flaw (CWE-88) in MikroTik RouterOS's SSH login path: when a login supplies a username beginning with a prohibited character, the RouterOS login helper mishandles the argument, allowing the trusted RouterOS policy mask to be changed and privileges to be escalated. An unauthenticated attacker only needs the ability to reach the router's SSH service, since exploitation happens during the SSH login process itself. By altering the policy mask the attacker gains elevated rights on the device, and news reports indicate attackers have used this technique — including logins with usernames such as '-2' — as part of chains that take over routers without needing a password. Any RouterOS deployment running versions before the fixes (6.49.21 Long-term, 7.23.4 Long-term, 7.24.2 Stable) with SSH enabled or reachable is affected, with internet-exposed SSH at highest risk. Multiple outlets report the RouterOS flaws are being actively exploited in the wild, although no public proof-of-concept is known and the flaw is not yet in CISA KEV.

Do: Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable) as applicable. Until patched, restrict SSH (TCP 22) to trusted management networks or disable the SSH service if unused, and review authentication logs and user/group policy settings for tampering — reports indicate attackers log in with usernames beginning with '-' (e.g., '-2').

9.2
group max
1% KEV PoC ×2
  • MikroTik RouterOS v6 (Long-term channel) versions prior to 6.49.21 (fixed in 6.49.21)
  • MikroTik RouterOS v7 (Long-term channel) versions prior to 7.23.4 (fixed in 7.23.4)
  • MikroTik RouterOS v7 (Stable channel) versions prior to 7.24.2 (fixed in 7.24.2)
mass≈1M+ devices: hundreds of thousands to over a million RouterOS devices are routinely observed internet-exposed, and far more expose SSH to the LAN
Full article374 words · extracted from gbhackers.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild.

On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations.

MikroTik RouterOS Flaws

CVE-2026-67277 is a missing-authentication vulnerability in the bandwidth-test service (btest) of MikroTik RouterOS. Classified under CWE-306, this issue could allow an attacker to disclose kernel memory and trigger a denial-of-service condition.

Exposing kernel memory is particularly serious, as leaked data may reveal sensitive information and help attackers bypass security measures during later stages of exploitation.

The second vulnerability, CVE-2026-86060, results from improper neutralization of argument delimiters in a command, tracked as CWE-88. According to the KEV entry, an attacker could manipulate the trusted RouterOS policy mask, potentially enabling privilege escalation.

An attacker who gains elevated permissions on a network router may alter routing rules, create persistence, intercept traffic, or use the device as a pivot point for further internal attacks.

CISA has designated CVE-2026-86060 as requiring forensic triage under Binding Operational Directive 26-04, indicating that affected organizations should investigate for signs of compromise in addition to applying mitigations.

Although CISA’s listing does not mention ransomware for either flaw, both are now classified as actively exploited vulnerabilities, making rapid assessment and remediation essential.

Federal Civilian Executive Branch agencies must adhere to the KEV remediation deadline. At the same time, CISA strongly urges all organizations operating MikroTik RouterOS devices to prioritize addressing these vulnerabilities.

Administrators should identify internet-exposed RouterOS systems, review vendor advisories for fixed releases or mitigations, restrict access to management and btest-service, and check device logs and configuration changes for signs of unauthorized activity.

The short three-day remediation window emphasizes CISA’s assessment that vulnerable RouterOS deployments pose an immediate operational risk. Organizations that cannot implement effective mitigations should consider removing affected devices from exposure until a secure configuration or updated software version is available.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/cisa-adds-exploited-mikrotik-routeros-flaws/