CVE-2026-67279: Mikrotik RouterOS Improper
Status: KEV
| Advisory ID: CVE-2026-67279
Key Details
| CVE | CVE-2026-67279 |
| Affected products | MikroTik RouterOS |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-841 (Improper Enforcement of Behavioral Workflow) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-25. |
| Federal remediation deadline | 2026-09-28 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | Industrial Network - Routers/Firewalls |
| Sectors | Multi-sector |
What to Know
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. (CISA)
What to Do
Monitor MikroTik's web page for any future patch releases.
References