Full Report
Mikrotik security advisory (AV26-887)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in MikroTik RouterOS
## CVE Details
- **CVE ID:** CVE-2026-67276, CVE-2026-67277, CVE-2026-86060
- **CVSS Score:** Not explicitly listed in advisory (Likely High/Critical based on exploitation status)
- **CWE:** Not specified in source article
## Affected Systems
- **Products:** MikroTik RouterOS
- **Versions:**
- Versions prior to 6.49.21
- Versions prior to 7.23.4
- Versions prior to 7.24.2
- Versions prior to 7.25 beta 3
- **Configurations:** Default or standard configurations running the affected RouterOS versions.
## Vulnerability Description
While the specific technical mechanics (e.g., buffer overflow, logic flaw) are not detailed in this summary advisory, these vulnerabilities affect the RouterOS software core. Historically, similar flaws in MikroTik devices involve the management interfaces (WinBox, WebFig) or specific network protocols that allow for unauthorized access or code execution.
## Exploitation
- **Status:** **Exploited in the wild.** Open-source reporting confirms active exploitation of these specific CVEs.
- **Complexity:** Not specified (typically Low for exploited-in-the-wild RouterOS flaws).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for data interception or credential theft)
- **Integrity:** High (Potential for unauthorized configuration changes or firmware modification)
- **Availability:** High (Potential for device bricking or service disruption)
## Remediation
### Patches
MikroTik has released the following patched versions to address these vulnerabilities:
- **RouterOS v6.x:** Upgrade to **6.49.21** or later.
- **RouterOS v7.x:** Upgrade to **7.23.4**, **7.24.2**, or **7.25 beta 3** (or later).
### Workarounds
- Restrict access to the MikroTik management interfaces (WinBox, WebFig, SSH, Telnet) using firewall rules to allow only trusted IP addresses.
- Disable unused services under `/ip service`.
- Ensure strong, unique passwords for all administrative accounts.
## Detection
- **Indicators of Compromise:** Monitor for unauthorized administrative logins, unusual firewall rule changes, or unexpected scripts in `/system script`.
- **Detection methods and tools:** Compare running version against the list of vulnerable versions. Check for the presence of unknown files in the router's storage.
## References
- **Vendor Advisory:** hxxps[://]mikrotik[.]com/supportsec/september-2026-vulnerability/
- **CERT.PL Advisory:** hxxps[://]cert[.]pl/en/posts/2026/09/mikrotik-routeros-cve/
- **Canadian Centre for Cyber Security:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/mikrotik-security-advisory-av26-887