What happened
CISA added CVE-2026-67279 to KEV on 25 Sept 2026; the workflow-enforcement flaw gives unauthenticated exec and chains into CVE-2026-86060 for full compromise.
Why it matters
Operational KEV signal for network infrastructure that may sit in front of or host AI/GPU nodes (networks hosting LLM inference); included for completeness per the KEV coverage rule, though not AI-specific.
Attack vector
An unauthenticated client can open a session channel and send an exec request (behavioral-workflow flaw) that chains to unauthenticated exploitation of CVE-2026-86060; CISA KEV addition 25 Sept 2026 confirms in-the-wild exploitation.
Affected systems
MikroTik RouterOS (improper enforcement of behavioral workflow; chains to CVE-2026-86060)
Mitigation
Apply MikroTik September 2026 security release; follow BOD 26-04 guidance (federal due 28 Sept 2026).