Friday, September 11, 2026

CISA Adds 2 MikroTik Vulnerabilities to KEV Catalog – 9-10-26

Yesterday, CISA announced that it was adding two vulnerabilities in the MikroTik OS to their Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: 

MikroTik reported both vulnerabilities on September 3rd, 2026. The two vulnerabilities were among six initially reported by Sławomir Rozbicki from CERT Polska, with fixed versions available. CERT Polska subsequently reported active exploitation in the wild on September 5th, citing proof-of-concept code developed by Nick Pratley using version diff analysis. 

Based upon the CERT Polska reports the following vulnerabilities may also end up being added to the KEV catalog: 

  • Improper verification of cryptographic signature - CVE-2026-67276, CVE-2026-67278,  
  • Improper enforcement of behavioral workflow - CVE-2026-67279, and 
  • Path traversal - CVE-2026-67281 

CISA has directed federal agencies using the affected products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

CISA has established a compliance date of September 13th, 2026. 

No comments:

 
/* Use this with templates/template-twocol.html */