CISA Adds a Fourth MikroTrick Bug to Its Exploited List
Security / news
CISA Adds a Fourth MikroTrick Bug to Its Exploited List
CVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.

CISA added a third bug from MikroTik's six-flaw September disclosure to its Known Exploited Vulnerabilities catalog on Sept. 25, giving federal agencies until Sept. 28 to patch a RouterOS SSH flaw the agency had left off the list for more than two weeks after flagging two of its siblings.
The newly added bug, CVE-2026-67279, lets an unauthenticated client complete an SSH key rekey and reach RouterOS's connection protocol without ever authenticating, then open a session channel and issue commands that create, overwrite or read files in the router's managed file namespace, including configuration and diagnostic data. CISA rates it 6.5 under CVSS 3.1, its lowest score of the four MikroTik bugs now on the list.
The batch this bug came from
CERT Polska disclosed six RouterOS flaws together on Sept. 3 under the campaign name MikroTrick: CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060. MikroTik shipped fixes the same day in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21. CERT Polska said it had already observed exploitation attempts beginning around Sept. 2, a day before the coordinated disclosure, with successful logins traced to the address 82.192.72.4 and further attempts from 103.102.31.18.
CISA's first move came Sept. 10, when it added CVE-2026-67277, a missing-authentication flaw in RouterOS's bandwidth-test service, and CVE-2026-86060, a privilege-escalation bug in the login helper, to its exploited catalog together. That pairing, not CVE-2026-67279, was the one federal agencies were told to prioritize first.
A second way to the same result
Bishop Fox adversarial operator Emilio Gallegos published an analysis on Sept. 17 arguing that CVE-2026-67279, on its own, crosses "the boundary that previously kept the client away from RouterOS's login process" without needing CVE-2026-67277 at all. Chained instead with CVE-2026-86060, whose login helper treats a username starting with a dash as a file-descriptor selector rather than a name, the pair reaches what Gallegos called full "administrative takeover on vulnerable RouterOS 7.x builds," the same end state CISA's Sept. 10 pairing produces by a different route.
CISA's 15-day gap between flagging that first pairing and adding CVE-2026-67279 means agencies patching strictly to the KEV catalog's own schedule had an unaddressed path to the same outcome sitting in their routers the whole time, unless they had already applied MikroTik's Sept. 3 update in full.
| CVE | CVSS 3.1 | Added to KEV | Role in the chain |
|---|---|---|---|
| CVE-2026-67276 | 9.2 | Not listed | RSA signature forgery |
| CVE-2026-67277 | 8.8 | Sept. 10, 2026 | Missing auth on bandwidth-test service |
| CVE-2026-86060 | 9.2 | Sept. 10, 2026 | Login-helper privilege escalation |
| CVE-2026-67279 | 6.5 | Sept. 25, 2026 | SSH rekey authentication bypass |

The bug still missing from the list
CVE-2026-67276, an RSA public-key verification flaw CERT Polska rated 9.2 and named among the batch's three most critical, still returns no result in CISA's catalog as of Sept. 26. It is the highest-rated of the six MikroTik bugs disclosed on Sept. 3, and it is the only one of the three CERT Polska singled out as most critical that CISA has not added to its exploited list, three weeks after disclosure.
CISA has not said why CVE-2026-67276 remains off the list, and neither CERT Polska nor MikroTik has published evidence that it is being exploited independently of the other five. This piece follows an earlier report on the same MikroTrick chain's first two KEV additions and a technical breakdown of the chain published the day CISA made its first move.
What to do now
RouterOS administrators running any version older than 7.25 beta 3, 7.24.2, 7.23.4 or 6.49.21 remain exposed to all six MikroTrick bugs regardless of which ones CISA has catalogued. MikroTik's Sept. 3 update fixes the underlying code for CVE-2026-67279 along with the rest of the batch; the Sept. 28 KEV deadline applies only to federal civilian agencies, but the router does not know the difference.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 03CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.
- 04ShinyHunters Claims a PeopleSoft Zero-Day Breached the FBIThe extortion group says it took 2 to 3 terabytes of personnel data on the night of Sept. 21, but the bureau has confirmed only that it is investigating a claim.