Cookie Consent by Free Privacy Policy Generator

CISA Adds MikroTik RouterOS Vulnerabilities to Known Exploited Vulnerabilities Catalogue

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalogue, based on evidence of active exploitation. The flaws, CVE-2026-67277 and CVE-2026-86060, involve missing authentication for critical functions and improper neutralisation of argument delimiters in commands. MikroTik routers are widely deployed in enterprise networks, internet service providers, and managed service environments globally, including across the UK. These vulnerabilities allow attackers to execute commands or gain unauthorised access to network infrastructure, potentially enabling lateral movement, traffic interception or persistent access to corporate networks.

Why this matters for UK organisations

While CISA's Known Exploited Vulnerabilities catalogue is a US federal requirement, it serves as a valuable reference for UK organisations because it reflects vulnerabilities that are being actively exploited in the wild. MikroTik devices are common in UK business networks, particularly in smaller enterprises, branch offices and managed service provider environments. If these routers are exposed to the internet or accessible from compromised internal networks, they represent a significant risk. Attackers who exploit these flaws can gain control of network infrastructure, intercept traffic, modify routing, or use the compromised devices as a foothold for further attacks. The operational impact includes potential loss of network visibility, unauthorised access to internal systems, and difficulty in detecting or removing persistent attacker presence. Network infrastructure is often treated as stable and low-maintenance, which can lead to firmware updates being delayed or overlooked. However, routers and network devices are high-value targets for attackers because they sit at the boundary between internal and external networks, handle all traffic flowing through the organisation, and often have privileged access to network segments and systems.

What to review

UK organisations using MikroTik RouterOS devices should review their network infrastructure inventory to identify all MikroTik routers, verify that they are running the latest firmware, and ensure that management interfaces are not exposed to the internet without strong authentication and access controls. Consider whether your network team has a process for tracking and responding to vulnerabilities in network infrastructure, not just endpoints and servers. Review whether you have visibility into firmware versions across your network estate, whether there is a regular schedule for applying network device updates, and whether management interfaces are protected by multi-factor authentication and restricted to trusted IP addresses. If MikroTik devices are deployed in branch offices or remote locations, ensure there is a process for updating them remotely and verifying that updates have been applied successfully. Clarify who is responsible for monitoring security advisories for network infrastructure, and ensure that your incident response plans account for scenarios where network devices may be compromised. If you use managed service providers to maintain network infrastructure, confirm that they have processes in place to monitor and patch vulnerabilities in network devices, and that you have visibility into the patch status of devices they manage on your behalf.

Source: CISA

News and blog posts
Infosecurity Magazine reports that a new Android malware strain called...
Today's brief highlights the importance of timely patching, clear ownership of...
Cloud security company Wiz has reported that attackers successfully chained two...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two...