CISA Flags Two MikroTik RouterOS Bugs as Actively Exploited

The signal in one glance
What you need to know
- CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating that exploitation has been observed in the wild.
- A KEV listing is a stronger operational signal than a newly published vulnerability announcement because CISA says there is evidence of active exploitation.
- Action: Search asset and configuration inventories for MikroTik RouterOS devices, recording versions, management interfaces, internet exposure, and business ownership.
What happened
CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating that exploitation has been observed in the wild. The entries are CVE-2026-67277, described as missing authentication for a critical function, and CVE-2026-86060, involving improper neutralization of argument delimiters in a command.