CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7038

As cited

Copy frozen at (site build).

vulnerabilities

AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

The Canadian Centre for Cyber Security issued Alert AL26-020 on September 10, 2026, warning of three vulnerabilities in MikroTik RouterOS: CVE-2026-67276 (improper signature verification allowing SSH access without a private key), CVE-2026-67277 (missing authentication for sensitive information disclosure), and CVE-2026-86060 (argument injection enabling privilege escalation). Both CVE-2026-67277 and CVE-2026-86060 were added to CISA's Known Exploited Vulnerabilities database on the same day. Organizations must upgrade to fixed versions across all RouterOS branches (6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3) and prioritize devices exposing SSH to the internet.

Why it matters: Organizations running MikroTik RouterOS with internet-facing SSH services face immediate risk of remote code execution, privilege escalation, and unauthorized access; patching and reviewing logs for compromise indicators are critical next steps.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary