Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

🚨SEVERITY: MEDIUM — CVSS 6.5Security Advisory

TL;DR 📌

  • Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
  • Highest CVSS: 6.5 (Medium).
  • Listed in CISA KEV (2026-09-25) — this is being exploited in the wild.
  • Fixed in 6.49.21, 7.23.4, 7.24.2 — upgrade to this release or later.
  • CVEs: CVE-2026-67279.

What it is

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

For leadership 🧭

Executive summary. Risk is Medium (CVSS 6.5) across any MikroTik kit you run. Follow the remediation in the vendor advisory within Immediate — CISA KEV entries carry a federal remediation deadline.

Why it matters:

  • Exposure depends on deployment topology and which access paths reach the affected component.
  • Treat internet-facing and management-plane instances as higher risk than internal-only ones.
  • Keep monitoring for abnormal authentication and configuration events until upgrades complete.

Now / Next / Later:

  • Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
  • Next: apply the remediation the advisory specifies, through an approved change window.
  • Later: add a control check so builds cannot drift back onto a vulnerable train.

Source