EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Mikrotik security advisory (AV26-887) – Update 2

Official source
EudorIA operational summary

What it means

Priority 95/100

Mikrotik ha rilasciato un advisory (AV26-887) che segnala vulnerabilità in RouterOS versioni precedenti a 6.49.21, 7.23.4, 7.24.2 e 7,25 beta 3. Le vulnerabilità sono state sfruttate in ambiente reale, con CVE-2026-67276, CVE-2026-67277 e CVE-2026-86060. L'azienda invita gli utenti a applicare le patch disponibili.

Why it matters

Le PMI che utilizzano RouterOS sono a rischio di attacchi di tipo sfruttamento di vulnerabilità, potenzialmente portando a compromissione di dispositivi e dati sensibili. L'assenza di patch potrebbe esporre le infrastrutture a minacce esterne.

Potential operational benefits

  • Riduzione della superficie esposta di dispositivi MikroTik
  • Miglioramento della protezione contro attacchi sfruttando vulnerabilità note
  • Aumento della resilienza in caso di compromissione
  • Miglioramento della gestione degli accessi e della sicurezza delle informazioni
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMFA / IdentitàMonitoraggio / SIEMBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Canadian Centre for Cyber Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Serial Number: AV26-887 Date: September 8, 2026 Updated: September 25, 2026 As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild. Update 1 On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67279 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities in Mikrotik RouterOS software September 2026 vulnerability CISA KEV: CVE-2026-67277 CISA KEV: CVE-2026-86060 CISA KEV: CVE-2026-67279

Source
Canadian Centre for Cyber Security (Canada)
Publishing entity
Canadian Centre for Cyber Security
Entity type
National CSIRT
Area
North America · CA
Original language
en · translation in preparation
Publication
25/09/2026 17:33
MITRE ATT&CK
T1190, T1486
CVE
CVE-2026-67276, CVE-2026-67277, CVE-2026-86060, CVE-2026-67279
Stated country
CA
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source