Mikrotik security advisory (AV26-887) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-887 Date: September 8, 2026 Updated: September 10, 2026 As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild. Update 1 On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities in Mikrotik RouterOS software September 2026 vulnerability CISA KEV: CVE-2026-67277 CISA KEV: CVE-2026-86060
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/mikrotik-security-advisory-av26-887
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-672760.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-67277Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 56% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-86060Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67276 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-67277 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-86060 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [kritisch] MikroTik RouterOS: Mehrere Schwachstellencert-bund
- criticalexploitedAL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060cccs
- criticalexploitedCISA Adds Two Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOSncsc-nl
- criticalexploitedCVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that beg…nvd
- highexploitedCVE-2026-67277: RouterOS accepts a "related" btest connection before the corresponding primary session has com…nvd
- unknownCVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication requ…nvd
More from Canadian Centre for Cyber Security
- criticalGitLab security advisory (AV26-917)2026-09-11
- unknownJFrog security advisory (AV26-867) – Update 22026-09-11
- unknownn8n security advisory (AV26-916)2026-09-11
- unknownConnectWise security advisory (AV26-903) – Update 12026-09-11
- criticalProgress security advisory (AV26-915)2026-09-11