we_are_coded.by CODE · The world, decoded
БГ
MikroTik

Two MikroTik RouterOS flaws are now used in attacks, and the fix dates from 3 September

CISA · event date: 10 September 2026Security

On 10 September CISA listed CVE-2026-86060 and CVE-2026-67277 in RouterOS as actively exploited, with a deadline of 13 September. MikroTik released the fixes a week earlier and advises keeping SSH closed to untrusted networks.

In short
  • CVE-2026-86060: changing the trusted policy mask and escalating privileges.
  • CVE-2026-67277: missing authentication in the btest service, which allows kernel memory disclosure and denial of service.
  • Fixes in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21; after updating, RouterOS checks whether the device has been compromised and, if so, marks it as Flagged.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

A week after the fix, two flaws in MikroTik's RouterOS entered the catalog of exploited vulnerabilities.

The facts: on 10 September 2026 CISA added two MikroTik RouterOS vulnerabilities to the KEV catalog with a deadline of 13 September. CVE-2026-86060 lets an attacker change the trusted RouterOS policy mask and escalate privileges. CVE-2026-67277 is missing authentication for a critical function in the btest service, which allows kernel memory disclosure and denial of service. On 3 September MikroTik published a bulletin announcing fixes in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21, saying most configurations are not at risk but upgrading is highly recommended, and advising that SSH not be open to untrusted networks. The bulletin links the vulnerabilities to the codename MikroTrick and to CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277, reported by CERT.pl. RouterOS itself checks whether the device has been compromised and marks it as Flagged in the log.

Three things to do

First, update to one of the fixed versions. According to MikroTik the option should already be in the check-for-updates menu.

Second, open the log and look for a critical entry saying the device is Flagged. If it is there, follow MikroTik's instructions, don't improvise.

Third, even if it isn't flagged, after updating go through the configuration for scripts, users or settings you don't recognise. That advice comes from the bulletin itself and is the most boring one, and boring advice is the easiest to skip.

The router nobody remembers is the router someone else has already found.

And one word on SSH. MikroTik blocks that port from outside by default. If you ever opened it by hand to get in from home, now is the time to close it and come in through a VPN, as they themselves advise.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog (official catalog)→MikroTik - September 2026 vulnerability, 03.09.2026
Original: https://wearecoded.com/en/articles/mikrotik-routeros-dve-dupki-v-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news