CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog
CISA added CVE-2026-67279 to KEV on September 25. The medium-severity flaw chains with CVE-2026-86060 to enable full unauthenticated exploitation of MikroTik RouterOS. Federal deadline is September 28.

CISA added a second MikroTik RouterOS vulnerability to its Known Exploited Vulnerabilities catalog on September 25. CVE-2026-67279, rated CVSS 6.5 (medium), now sits alongside CVE-2026-86060 in the KEV catalog. The two are not independent findings. They form an exploitation chain.
CVE-2026-67279 involves an improper enforcement of behavioral workflow in RouterOS’s SSH session handling. An unauthenticated client can open a session channel and send an exec request through the affected code path. That access functions as the entry point for chaining into CVE-2026-86060, the CVSS 9.8 critical argument-handling flaw that allows privilege escalation. The combined chain gives an unauthenticated attacker code execution with elevated privileges on the router.
CISA’s remediation deadline for CVE-2026-67279 is September 28, 2026 for federal civilian agencies under BOD 26-04. CVE-2026-86060 was added on September 10 with a September 13 deadline. If you responded to the September 10 KEV entry but didn’t yet address both CVEs, you’ve patched one end of the chain and left the other open.
Fixed versions for CVE-2026-86060 are RouterOS 6.49.21, 7.23.4 (long-term), and 7.24.2 (stable). Consult MikroTik’s security advisory page and the NVD record for CVE-2026-67279 for patching specifics against the session-channel flaw. If you run internet-facing MikroTik SSH, block that access at the perimeter until patched and move device management to an out-of-band interface.
MikroTik routers are deployed widely in enterprise and ISP networks. Internet-facing devices with unpatched SSH are the kind of thing that gets swept up into botnet infrastructure when exploitable vulnerabilities become known. That is part of the reasoning behind CISA’s tight three-day deadline.
Related: MikroTik Patches Exploited SSH Auth Bypass, CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw.
- [ MEDIUM ]CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- [ CRITICAL ]CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Found this useful? Share it.
