Showing posts with label MikroTik. Show all posts
Showing posts with label MikroTik. Show all posts

Friday, September 11, 2026

CISA Adds 2 MikroTik Vulnerabilities to KEV Catalog – 9-10-26

Yesterday, CISA announced that it was adding two vulnerabilities in the MikroTik OS to their Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities are: 

MikroTik reported both vulnerabilities on September 3rd, 2026. The two vulnerabilities were among six initially reported by SÅ‚awomir Rozbicki from CERT Polska, with fixed versions available. CERT Polska subsequently reported active exploitation in the wild on September 5th, citing proof-of-concept code developed by Nick Pratley using version diff analysis. 

Based upon the CERT Polska reports the following vulnerabilities may also end up being added to the KEV catalog: 

  • Improper verification of cryptographic signature - CVE-2026-67276, CVE-2026-67278,  
  • Improper enforcement of behavioral workflow - CVE-2026-67279, and 
  • Path traversal - CVE-2026-67281 

CISA has directed federal agencies using the affected products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

CISA has established a compliance date of September 13th, 2026. 

Thursday, July 30, 2026

Review – 11 Advisories and 1 Update Published – 7-30-26

Today CISA’s NCCIC-ICS published 11 control system security advisories for products from MZ Automation (2), Watchfire, 06 Automation, Mitsubishi Electric, NASA, Rockwell Automation, Schneider Electric, Toptech, Johnson Controls, and MikroTik. They also updated an advisory for products from Hardy Barth. 

Advisories  

MZ Automation Advisory #1 - This advisory describes two vulnerabilities in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes eight vulnerabilities in the MZ Automation GmbH libiec61850. 

Watchfire Advisory - This advisory describes a hard-coded cryptographic key vulnerability in the Watchfire Controller Software. 

06 Automation Advisory - This advisory describes four vulnerabilities in the o6 Automation open62541 OPC UA stack. 

Mitsubishi Advisory - This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Mitsubishi CC-Link IE TSN Communication Protocol. 

NASA Advisory - This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application. 

NOTE: This vulnerability is related to an incomplete fix for CVE 2026-15352. 

Rockwell Advisory - This advisory describes an improper check for certificate revocation vulnerability in the Rockwell CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module. 

Schneider Advisory - This advisory describes an out-of-bounds write vulnerability in the Schneider IGSS. 

Toptech Advisory - This advisory describes a missing authentication for critical function vulnerability in the Toptech Systems RCU II+ and Multiload II+. 

Johnson Controls Advisory - This advisory describes three vulnerabilities in the Johnson Controls OpenBlue Employee smart building ecosystem. 

MikroTik Advisory - This advisory describes an insufficient session expiration vulnerability in the MikroTik RouterOS. 

Updates  

Hardy Barth Update -  This update provides additional information on the Salia EV Charge Controller advisory that was originally published on April 21st, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-advisories-and-1-update-published-68f  - subscription required. 

Tuesday, July 28, 2026

Review – 7 Advisories Published – 7-28-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from ABB, igloohome, MikroTik, and Siemens (4). 

Advisories  

ABB Advisory - This advisory describes a missing support for integrity check vulnerability in the ABB KNX Update Tool. The ABB advisory reports that: “As classic KNX technology did not include built-in encryption, this vulnerability is not specific to ABB products and cannot be addressed through a software update.” 

Igloohome Advisory - This advisory describes an inclusion of sensitive information in source code vulnerability in the igloohome Smart Lock Mobile Application (Android). 

MikroTik Advisory - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the MikroTik RouterOS and MikroTik Cloud Hosted Router. 

Siemens Advisory #1 - This advisory discusses more than 353 GNU/Linux vulnerabilities in the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. 

Siemens Advisory #2 - This advisory describes an allocation of resources without limit or throttling vulnerability in the Siemens SIMATIC S7-PLCSIM Advanced. 

Siemens Advisory #3 - This advisory describes an insecure inherited permissions vulnerability in the Siemens Mendix Runtime product. 

Siemens Advisory #4 - This advisory discusses an out-of-bounds write vulnerability in the Siemens Desigo CC products. 


For more information on these advisories, including DTRH looks at the Mendix vulnerability and Desigo CC exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-28-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */