← Knowledge Center
Zero-Day CVE-2026-67277, CVE-2026-86060

CISA Flags Actively Exploited MikroTik RouterOS Auth Bypass in KEV Catalog

CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. CVE-2026-67277 is a missing-authentication-for-critical-function flaw, while CVE-2026-86060 involves improper neutralization of argument delimiters in a command. The authentication bypass is especially relevant from an identity/access perspective, as it can allow attackers to reach privileged functions without valid credentials.

Edge devices like routers are common footholds for attackers seeking to pivot into internal networks, intercept traffic, or stage credential theft against domain and directory infrastructure. Under BOD 26-04, federal civilian agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets that grant full control post-exploitation, and check whether systems were already compromised before patching.

What to take away: patch affected MikroTik RouterOS devices immediately, and treat exposed edge gear as a potential entry point into your identity infrastructure—review for signs of prior compromise, not just apply the fix.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.