Serial Number: AV26-887
Date: September 8, 2026
Updated: September 25, 2026
As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product:
- RouterOS
- Prior to 6.49.21
- Prior to 7.23.4
- Prior to 7.24.2
- Prior to 7.25 beta 3
Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild.
Update 1
On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database.
Update 2
On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67279 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.