Mikrotik security advisory (AV26-887) – Update 2
What it means
Mikrotik ha rilasciato un advisory (AV26-887) che segnala vulnerabilità in RouterOS versioni precedenti a 6.49.21, 7.23.4, 7.24.2 e 7,25 beta 3. Le vulnerabilità sono state sfruttate in ambiente reale, con CVE-2026-67276, CVE-2026-67277 e CVE-2026-86060. L'azienda invita gli utenti a applicare le patch disponibili.
Why it matters
Le PMI che utilizzano RouterOS sono a rischio di attacchi di tipo sfruttamento di vulnerabilità, potenzialmente portando a compromissione di dispositivi e dati sensibili. L'assenza di patch potrebbe esporre le infrastrutture a minacce esterne.
Recommended actions
- Applicare immediatamente le patch disponibili per RouterOS
- Verificare la versione corrente di RouterOS e applicare le patch necessarie
- Ridurre l'esposizione di dispositivi MikroTik su reti pubbliche
- Implementare controlli di accesso e autenticazione multi-fattore
- Eseguire backup regolari e verificare la loro integrità
- Monitorare attivamente i log e le attività di rete per rilevare comportamenti anomali
Potential operational benefits
- Riduzione della superficie esposta di dispositivi MikroTik
- Miglioramento della protezione contro attacchi sfruttando vulnerabilità note
- Aumento della resilienza in caso di compromissione
- Miglioramento della gestione degli accessi e della sicurezza delle informazioni
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Serial Number: AV26-887 Date: September 8, 2026 Updated: September 25, 2026 As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild. Update 1 On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67279 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities in Mikrotik RouterOS software September 2026 vulnerability CISA KEV: CVE-2026-67277 CISA KEV: CVE-2026-86060 CISA KEV: CVE-2026-67279
- Source
- Canadian Centre for Cyber Security (Canada)
- Publishing entity
- Canadian Centre for Cyber Security
- Entity type
- National CSIRT
- Area
- North America · CA
- Original language
- en · translation in preparation
- Publication
- 25/09/2026 17:33
- MITRE ATT&CK
- T1190, T1486
- CVE
- CVE-2026-67276, CVE-2026-67277, CVE-2026-86060, CVE-2026-67279
- Stated country
- CA
Affected products and versions
The collector will check NVD and the available official vendor advisories.