Executive Summary
CISA added two critical MikroTik RouterOS vulnerabilities (CVE-2026-67277 and CVE-2026-86060) to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026 following evidence of active exploitation. CVE-2026-67277 involves missing authentication for critical functions, while CVE-2026-86060 relates to improper neutralization of argument delimiters in commands. These vulnerabilities affect network infrastructure devices and allow attackers to gain total control of compromised systems, posing significant risks to federal and enterprise networks.
This addition reinforces the critical importance of rapid vulnerability remediation as network infrastructure attacks continue to surge, with threat actors increasingly targeting edge devices and routers to establish persistent footholds for lateral movement and data exfiltration campaigns.
Why This Matters Now
Network infrastructure vulnerabilities are experiencing unprecedented exploitation rates, with nation-state actors and cybercriminals actively targeting edge devices to bypass traditional security controls and establish persistent access points for widespread compromise campaigns.
Attack Path Analysis
Attackers exploited MikroTik RouterOS vulnerabilities (CVE-2026-67277 and CVE-2026-86060) to gain initial access through missing authentication and command injection flaws. They escalated privileges through router configuration manipulation, moved laterally across network segments via compromised routing infrastructure, established command and control through router-based tunneling, exfiltrated data through unencrypted traffic interception, and maintained persistent access for ongoing operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of MikroTik RouterOS missing authentication vulnerability (CVE-2026-67277) and command injection flaw (CVE-2026-86060) to gain unauthorized access to network infrastructure devices
Related CVEs
CVE-2024-67277
CVSS 9.8A missing authentication vulnerability in MikroTik RouterOS allows unauthenticated remote attackers to access critical functions and potentially execute arbitrary commands.
Affected Products:
MikroTik RouterOS – < 7.15.2
Exploit Status:
exploited in the wildCVE-2024-86060
CVSS 8.1An improper neutralization of argument delimiters vulnerability in MikroTik RouterOS allows attackers to inject malicious commands through crafted input parameters.
Affected Products:
MikroTik RouterOS – < 7.15.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Impair Defenses: Disable or Modify Tools
Command and Scripting Interpreter: Unix Shell
Process Injection
Exploitation for Privilege Escalation
Remote System Discovery
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Updates
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Asset Management and Vulnerability Assessment
Control ID: Identity.AM-2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
MikroTik RouterOS vulnerabilities expose critical network infrastructure to authentication bypass and command injection attacks, compromising encrypted traffic and enabling lateral movement.
Government Administration
Federal agencies face BOD 26-04 compliance requirements for rapid remediation of these KEV catalog vulnerabilities on publicly exposed RouterOS assets granting total control.
Financial Services
Network infrastructure vulnerabilities threaten PCI compliance requirements while compromising east-west traffic security and egress filtering controls protecting sensitive financial data flows.
Health Care / Life Sciences
RouterOS exploitation risks HIPAA compliance violations through compromised network segmentation, unencrypted traffic exposure, and potential lateral movement accessing protected health information systems.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- MikroTik RouterOS Security Updates and Changelogshttps://mikrotik.com/download/changelogsVerified
- Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskhttps://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-riskVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain this MikroTik infrastructure compromise by limiting lateral movement between network segments and reducing the blast radius of router-based attacks through workload isolation and controlled traffic flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Compromised router access would likely have reduced reachability to cloud workloads through identity-aware routing policies that isolate infrastructure management from application traffic flows
Control: Zero Trust Segmentation
Mitigation: Administrative privilege escalation attempts would likely be constrained through microsegmentation policies that limit configuration scope and prevent unauthorized routing table modifications across network segments
Control: East-West Traffic Security
Mitigation: Cross-segment pivoting capabilities would likely be significantly reduced through enforced traffic inspection and workload-to-workload communication policies that prevent unauthorized network traversal
Control: Multicloud Visibility & Control
Mitigation: Covert command and control establishment would likely be constrained through centralized visibility that detects anomalous communication patterns and unauthorized traffic flows across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration through traffic interception would likely be reduced through controlled egress policies that limit unauthorized outbound data flows and enforce encryption requirements for sensitive communications
Residual infrastructure access would likely maintain reduced scope for intelligence collection due to workload isolation boundaries that limit exposure of sensitive application data and inter-service communications
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- Internet Connectivity Services
- Remote Access Systems
- Network Security Operations
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of network configuration data, routing tables, and administrative credentials for organizations using vulnerable MikroTik RouterOS devices in critical network infrastructure roles.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block exploitation attempts against known vulnerabilities like CVE-2026-67277 and CVE-2026-86060
- • Deploy encrypted traffic controls (HPE) with MACsec and IPsec to protect data in transit from router-based interception and exfiltration
- • Establish zero trust segmentation with microsegmentation policies to prevent lateral movement through compromised network infrastructure
- • Enable multicloud visibility and control to detect anomalous routing behaviors and suspicious network configuration changes
- • Implement egress security and policy enforcement to prevent unauthorized data exfiltration through compromised network devices



