As cited
Copy frozen at (site build).
vulnerabilities
AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
The Canadian Centre for Cyber Security issued Alert AL26-020 on September 10, 2026, warning of three vulnerabilities in MikroTik RouterOS: CVE-2026-67276 (improper signature verification allowing SSH access without a private key), CVE-2026-67277 (missing authentication for sensitive information disclosure), and CVE-2026-86060 (argument injection enabling privilege escalation). Both CVE-2026-67277 and CVE-2026-86060 were added to CISA's Known Exploited Vulnerabilities database on the same day. Organizations must upgrade to fixed versions across all RouterOS branches (6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3) and prioritize devices exposing SSH to the internet.
Why it matters: Organizations running MikroTik RouterOS with internet-facing SSH services face immediate risk of remote code execution, privilege escalation, and unauthorized access; patching and reviewing logs for compromise indicators are critical next steps.
- Source published
- First seen by Cybersecurity Tracker