CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Summary
MikroTik RouterOS has a vulnerability (CVE-2026-67279) that allows unauthenticated clients to open a session and send exec requests, potentially chaining to exploit CVE-2026-86060 for unauthenticated exploitation. Affected stakeholders must apply vendor mitigations and comply with CISA's BOD 26-04 guidance for prioritizing security updates.
IFF Assessment
This vulnerability allows unauthenticated access and exploitation, posing a direct risk to the security of MikroTik devices and potentially enabling further compromise.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 28, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in MikroTik RouterOS presents a significant risk, especially as it can be chained with another known exploit for unauthenticated exploitation. Defenders should prioritize patching and implementing vendor-provided mitigations on all exposed MikroTik devices. The CISA KEV listing indicates a high priority for remediation.