CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

criticalknown exploitedpublic exploitCVE-2026-67276CVE-2026-67277CVE-2026-86060
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Number: AL26-020 Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1 . In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2 . Tracked as CVE-2026-67277 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information. Tracked as CVE-2026-86060 Footnote 5 , this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88) Footnote 6 that may allow a remote attacker to escalate privileges. Tracked as CVE-2026-67276 Footnote 7 , this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347) Footnote 8 that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key. On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Footnote 9 Footnote 10 Suggested actions The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-09-10
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-67276coverage & exploitation statusNVD · CVE.org
CVE-2026-67277coverage & exploitation statusNVD · CVE.org
CVE-2026-86060coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security