HIGHVulnerability
Verified
Global

CISA KEV: MikroTik RouterOS — Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Analysis

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-25. Remediation due: 2026-09-28.

Indicators of Compromise (2)

CVE (2)
CVE-2026-86060
CVE-2026-67279
Source Attribution

Originally published by CISA KEV on Sep 25, 2026. Verified by: CISA.

Related Threats