Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-67279: MikroTik RouterOS

Mikrotik RouterOS包含了行為工作流程脆弱性的不當執行,可以讓一個未經認證的客戶端開啟會話通道併傳送執行請求。這種脆弱性可以被連鎖起來,以實現對CVE-2026-86060的未經認證的開發。

CISA (English)

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

廠商
MikroTik
產品
RouterOS
漏洞
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
加入日期
2026年9月25日
CISA 修補期限(美國聯邦機關)
2026年9月28日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-841

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02