← Blog · · df00tech

MikroTik RouterOS Auth-Bypass Flaw Chains to Unauthenticated Exploit of CVE-2026-86060, Added to CISA KEV

breaking kev MikroTik CVE-2026-67279

CISA has added CVE-2026-67279, a MikroTik RouterOS vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild. According to MikroTik's security advisory, the flaw is described as an "improper enforcement of behavioral workflow" issue that allows an unauthenticated client to open a session channel and send an exec request. MikroTik states this weakness can be chained to achieve unauthenticated exploitation of a separate vulnerability, CVE-2026-86060.

Why It Matters

RouterOS runs on a large installed base of MikroTik routers used across enterprise, ISP, and small-office/home-office environments, many of which are internet-facing for remote management. A vulnerability that lets an unauthenticated attacker open a session and issue commands removes the authentication barrier that would normally limit exploitation to credentialed or adjacent-network attackers. Because it enables unauthenticated exploitation of CVE-2026-86060, the practical severity of that second vulnerability is elevated regardless of its standalone rating. KEV inclusion signals this is not theoretical — CISA requires evidence of real-world exploitation before adding an entry, so organizations running affected RouterOS versions should treat this as an active threat, not a future risk.

What Defenders Should Do Now

  • Identify all MikroTik RouterOS devices in your environment, especially any exposing management interfaces (SSH, Winbox, API, or web) to the internet.
  • Consult MikroTik's advisory for affected RouterOS versions and apply patches or vendor-recommended mitigations as soon as they are available.
  • Restrict access to router management services to trusted management networks or VPNs; disable unauthenticated or unnecessary services where possible.
  • Hunt for anomalous session/exec activity on RouterOS devices — unexpected new sessions, configuration changes, or command execution not tied to known administrative activity.
  • Review router logs and NetFlow/traffic data for connections to management ports from unexpected external sources.
  • Treat any RouterOS device that cannot be immediately patched as high-risk and prioritize compensating network controls (segmentation, access lists, disabling exposed services).

This is developing intelligence based on a same-day CISA KEV addition and MikroTik's own advisory; full technical details, affected version ranges, and indicators of compromise may evolve as more information is published. For authoritative details, see MikroTik's official security advisory.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.