Skip to main content

CareScope Watch/Cybersecurity/September 10, 2026

CISA Warns of Actively Exploited MikroTik RouterOS Vulnerabilities

CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The flaws include CVE-2026-67277, a missing authentication vulnerability for a critical function, and CVE-2026-86060, an improper neutralization of argument delimiters in a command.

Why it matters

CISA notes that these vulnerabilities serve as frequent attack vectors for malicious cyber actors. When present on publicly exposed assets, such vulnerabilities can grant attackers total control over the affected system post-exploitation.

What it means for your practice

Practices and their IT providers should determine if MikroTik RouterOS equipment is in use on their networks and prioritize rapid remediation. In accordance with CISA guidance, organizations should also check whether systems were compromised before applying updates.