AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 2 of 2 flaws named
- Flaws named
- CVE-2026-67277CVE-2026-86060
- Reported by
- 1 outlet
Audience
This Alert is intended for IT professionals and managers.
Purpose
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Details
The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1.
In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2.
Tracked as CVE-2026-67277Footnote 3, this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information.
Tracked as CVE-2026-86060Footnote 5, this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88)Footnote 6 that may allow a remote attacker to escalate privileges.
Tracked as CVE-2026-67276Footnote 7, this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347)Footnote 8 that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key.
On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Footnote 9Footnote 10
Suggested actions
The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletinFootnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions:
Upgrade affected Cisco ASA instances to a fixed version:
| Affected product | Affected versions | Fixed versions |
|---|---|---|
| RouterOS 6.x | Versions prior to 6.49.21 | Version 6.49.21 |
| RouterOS 7.x Long-Term | Versions prior to 7.23.4 | Version 7.23.4 |
| RouterOS 7.x Stable | Versions prior to 7.24.2 | Version 7.24.2 |
| RouterOS Development Branch | Versions prior to 7.25 beta 3 | Version 7.25 beta 3 |
The Cyber Centre recommends following guidance provided by MikroTikFootnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status siteFootnote 12.
The Cyber Centre also recommends organizations to:
- Determine the current version of software on each appliance.
- Prioritize patching for systems exposing SSH to the internet.
- Monitor authentication logs and network activity for indications of unauthorized access.
- After patching, verify that the appliance is running the updated version and review logs for unusual activity.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security ActionsFootnote 13 with an emphasis on the following topics:
- Consolidate, monitor, and defend Internet gateways
- Patch operating systems and applications
- Harden operating systems and applications
- Isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca.
References
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-672778.2High
MikroTik RouterOS
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Used in attacksAdded to CISA's list 2026-09-10 · Exploit code published · Patch or advisory available
Full record → - CVE-2026-860609.8Critical
MikroTik RouterOS
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.
Used in attacksAdded to CISA's list 2026-09-10 · Exploit code published · Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-09-10 19:50 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited