Vulnerability  ·  2026-09-26

KEV: MikroTik RouterOS unauthenticated session/exec chain (CVE-2026-67279 + CVE-2026-86060)

VulnerabilityLow impactGlobalCVE-2026-67279
CISA added CVE-2026-67279 to KEV on 25 Sept 2026; the workflow-enforcement flaw gives unauthenticated exec and chains into CVE-2026-86060 for full compromise.
Operational KEV signal for network infrastructure that may sit in front of or host AI/GPU nodes (networks hosting LLM inference); included for completeness per the KEV coverage rule, though not AI-specific.
An unauthenticated client can open a session channel and send an exec request (behavioral-workflow flaw) that chains to unauthenticated exploitation of CVE-2026-86060; CISA KEV addition 25 Sept 2026 confirms in-the-wild exploitation.
MikroTik RouterOS (improper enforcement of behavioral workflow; chains to CVE-2026-86060)
Apply MikroTik September 2026 security release; follow BOD 26-04 guidance (federal due 28 Sept 2026).
CISA KEV catalogMikroTik September 2026 vulnerability
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →