Saturday, September 26, 2026

CISA Adds Mikrotik Vulnerability to KEV Catalog – 9-25-26

Yesterday, CISA announced that it had added an improper enforcement of behavioral Workflow vulnerability in the Mikrotik RouterOS to their Known Exploited Vulnerabilities (KEV) catalog. CERT-PL announced this vulnerability (along with five others) on September 5th, 2026. Mikrotik released three new versions (here, here, and here) that mitigate the vulnerability on September 3rd, 2026, with further updates released on September 22nd.  

On September 4th, Nick Pratley published a technical analysis of the Mikrotik vulnerability based upon his version differential analysis (using AI tools to speed the analysis); includes a limited effect proof-of-concept code. On September 17th, Bishop Fox published an article describing evidence that the six vulnerabilities were being exploited in the wild before Mikrotik published their updated versions, confirming a similar report from CERT.PL published on September 5th, 2026. 

CISA is requiring federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements” [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of September 28th, 2026, has been established. 

No comments:

 
/* Use this with templates/template-twocol.html */