AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

ExploitedCriticalCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1.

In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2.

Tracked as CVE-2026-67277Footnote 3, this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information.

Tracked as CVE-2026-86060Footnote 5, this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88)Footnote 6 that may allow a remote attacker to escalate privileges.

Tracked as CVE-2026-67276Footnote 7, this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347)Footnote 8 that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key.

On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Footnote 9Footnote 10

Suggested actions

The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletinFootnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions:

Upgrade affected Cisco ASA instances to a fixed version:

Affected product Affected versions Fixed versions
RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21
RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4
RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2
RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3

The Cyber Centre recommends following guidance provided by MikroTikFootnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status siteFootnote 12.

The Cyber Centre also recommends organizations to:

  • Determine the current version of software on each appliance.
  • Prioritize patching for systems exposing SSH to the internet.
  • Monitor authentication logs and network activity for indications of unauthorized access.
  • After patching, verify that the appliance is running the updated version and review logs for unusual activity.

In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security ActionsFootnote 13 with an emphasis on the following topics:

  • Consolidate, monitor, and defend Internet gateways
  • Patch operating systems and applications
  • Harden operating systems and applications
  • Isolate web-facing applications

Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca.

References

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

At a glance

Severity
Criticalfrom category and source signals; no CVSS referenced
Exploitation
Confirmed — 2 of 2 referenced vulnerabilities are on the CISA Known Exploited Vulnerabilities catalogue
Vendors & products
None named
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-10 19:50 UTC
Priority
79/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Vulnerabilities referenced

  • CVE-2026-67277Exploited· due 2026-09-13

    MikroTik RouterOS

    MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

    Added to KEV 2026-09-10

    Full record →
  • CVE-2026-86060Exploited· due 2026-09-13

    MikroTik RouterOS

    MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

    Added to KEV 2026-09-10

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-10 19:50 UTC

Related stories