Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-67279: MikroTik RouterOS

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Vendor
MikroTik
Product
RouterOS
Vulnerability
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Date added
Sep 25, 2026
CISA due date (U.S. federal agencies)
Sep 28, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-841

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02