On 10 September CISA listed CVE-2026-86060 and CVE-2026-67277 in RouterOS as actively exploited, with a deadline of 13 September. MikroTik released the fixes a week earlier and advises keeping SSH closed to untrusted networks.
- CVE-2026-86060: changing the trusted policy mask and escalating privileges.
- CVE-2026-67277: missing authentication in the btest service, which allows kernel memory disclosure and denial of service.
- Fixes in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21; after updating, RouterOS checks whether the device has been compromised and, if so, marks it as Flagged.
A week after the fix, two flaws in MikroTik's RouterOS entered the catalog of exploited vulnerabilities.
Three things to do
First, update to one of the fixed versions. According to MikroTik the option should already be in the check-for-updates menu.
Second, open the log and look for a critical entry saying the device is Flagged. If it is there, follow MikroTik's instructions, don't improvise.
Third, even if it isn't flagged, after updating go through the configuration for scripts, users or settings you don't recognise. That advice comes from the bulletin itself and is the most boring one, and boring advice is the easiest to skip.
And one word on SSH. MikroTik blocks that port from outside by default. If you ever opened it by hand to get in from home, now is the time to close it and come in through a VPN, as they themselves advise.