logo

CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges

ID: 8bf0da3e-a14c-5607-a97a-5a99cac5ebd2

STIX ID: report--8bf0da3e-a14c-5607-a97a-5a99cac5ebd2

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Tamilselvan

...
...

**Executive Summary:** CISA added two MikroTik RouterOS vulnerabilities to its KEV Catalog — CVE-2026-86060, an actively exploited privilege-escalation bug that can alter trusted policy masks and grant elevated router privileges, and CVE-2026-67277, a missing-authentication flaw that may cause kernel-memory disclosure and DoS. Affected organizations are urged to identify exposed RouterOS devices, apply vendor mitigations, perform forensic triage for CVE-2026-86060, and review logs for suspicious configuration changes and privileged activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.