CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-67277 and CVE-2026-86060, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities affect MikroTik RouterOS and are considered significant attack vectors. Binding Operational Directive (BOD) 26-04 requires federal agencies to prioritize remediation of these types of high-risk vulnerabilities.

IFF Assessment

FOE

The addition of actively exploited vulnerabilities to CISA's KEV catalog represents a direct threat to organizations that have not patched them, indicating immediate risks for defenders.

Severity

CISA KEV: Listed as actively exploited. Federal patch due: September 13, 2026. Known ransomware use: Unknown.

Defender Context

Organizations should immediately review their systems for the newly added MikroTik RouterOS vulnerabilities and prioritize patching. The KEV catalog serves as a critical indicator for actively exploited threats, and adherence to CISA's directives, particularly BOD 26-04, is crucial for federal agencies in managing risk effectively.

Read Full Story →