VYPR
Published Sep 10, 2026· Updated Sep 11, 2026· 1 source

Mikrotik: 2 Actively-Exploited Flaws Added to CISA KEV

Key findings • Two actively-exploited Mikrotik vulnerabilities, CVE-2026-67277 and CVE-2026-86060, added to CISA KEV. • Inclusion in KEV confirms active exploitation by threat actors in the w…

Key findings

  • Two actively-exploited Mikrotik vulnerabilities, CVE-2026-67277 and CVE-2026-86060, added to CISA KEV.
  • Inclusion in KEV confirms active exploitation by threat actors in the wild.
  • All organizations using Mikrotik devices should prioritize immediate patching and remediation.
  • Failure to address these flaws can lead to significant security compromises.
  • CISA's KEV catalog mandates timely remediation for federal agencies, setting a critical standard for all.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding two Mikrotik vulnerabilities, CVE-2026-67277 and CVE-2026-86060, which have been confirmed as actively exploited in the wild. These flaws were added to CISA's Known Exploited Vulnerabilities (KEV) Catalog on September 10, 2026, underscoring the immediate threat they pose to network security.

The inclusion of a vulnerability in the KEV Catalog signifies that threat actors are actively leveraging the flaw to compromise systems. For federal civilian executive branch (FCEB) agencies, this designation mandates remediation within a specific timeframe, typically a matter of weeks, to mitigate the risk. However, the active exploitation status means all organizations using affected Mikrotik devices should treat these vulnerabilities with extreme urgency.

  • **CVE-2026-67277**: This actively exploited Mikrotik vulnerability presents a significant risk, requiring immediate attention from network administrators.
  • **CVE-2026-86060**: Another actively exploited flaw impacting Mikrotik products, this CVE also demands prompt patching to prevent potential compromise.

The presence of these vulnerabilities in the KEV Catalog highlights the critical need for robust vulnerability management practices. Organizations must ensure they have a clear understanding of their asset inventory and a swift patching process to address such high-priority threats. Failure to remediate actively exploited flaws can lead to unauthorized access, data breaches, and disruption of services.

Defenders are strongly advised to identify all Mikrotik devices within their environments and apply the latest security updates provided by the vendor without delay. Adhering to CISA's remediation deadlines for KEV entries is crucial for federal agencies, but all organizations should consider these timelines as best practice for any actively exploited vulnerability. Proactive patching and continuous monitoring are essential to defend against sophisticated threat actors targeting known weaknesses.

Synthesized by Vypr AI