Federal cybersecurity authorities have issued an emergency addition to the Known Exploited Vulnerabilities catalog, ordering mandatory remediation for two edge routing vulnerabilities actively exploited in wild network attacks. Threat actors leverage missing authentication handlers and command delimiter injection bugs to hijack internet-exposed routers.
The catalog additions cover missing authentication vulnerability CVE-2026-67277 and command argument delimiter vulnerability CVE-2026-86060 affecting MikroTik RouterOS installations. Unauthenticated remote actors transmit malformed network sequences to public SSH and management interfaces to bypass login verification, execute root system commands, and plant rogue user accounts formatted as ssh:-2@. Under Binding Operational Directive 26-04, federal civilian executive branch agencies face a mandatory September 25 compliance deadline to apply vendor software updates and conduct forensic triage.
Subverting perimeter routing appliances destroys network access boundaries across corporate subnets. Because RouterOS devices manage edge traffic routing, local firewall rules, and VPN tunnel terminations, an unauthenticated takeover permits adversaries to intercept unencrypted transit traffic, modify DNS routing records, and pivot into internal enterprise networks.
– Force immediate installation of RouterOS software updates published by MikroTik across all edge routing appliances.
– Restrict public internet access to RouterOS management services including SSH, WinBox, and WebFig using strict firewall access lists.
– Check appliance status using the system device-mode print command to verify whether the device has been set to Flagged.
– Perform complete system resets and configuration rebuilds from verified clean backups if rogue account entries are identified.
Perimeter network protection demands strict management interface isolation and immediate firmware maintenance updates to ensure edge gateways remain protected from unauthenticated remote administrative takeover. #CodeDefence #MikroTik #RouterOS #CISA #KEV #EdgeSecurity #NetworkSecurity #AppSec
/
