Alert - AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

Number: AL26-020
Date: September 10, 2026

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1.

In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2.

Tracked as CVE-2026-67277Footnote 3, this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information.

Tracked as CVE-2026-86060Footnote 5, this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88)Footnote 6 that may allow a remote attacker to escalate privileges.

Tracked as CVE-2026-67276Footnote 7, this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347)Footnote 8 that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key.

On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Footnote 9Footnote 10

Suggested actions

The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletinFootnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions:

Upgrade affected Cisco ASA instances to a fixed version:

Affected product Affected versions Fixed versions
RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21
RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4
RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2
RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3

The Cyber Centre recommends following guidance provided by MikroTikFootnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status siteFootnote 12.

The Cyber Centre also recommends organizations to:

  • Determine the current version of software on each appliance.
  • Prioritize patching for systems exposing SSH to the internet.
  • Monitor authentication logs and network activity for indications of unauthorized access.
  • After patching, verify that the appliance is running the updated version and review logs for unusual activity.

In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security ActionsFootnote 13 with an emphasis on the following topics:

  • Consolidate, monitor, and defend Internet gateways
  • Patch operating systems and applications
  • Harden operating systems and applications
  • Isolate web-facing applications

Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca.

References

Date modified: