AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

Imported from official source

Cybersecurity Classified by Officially

Number: AL26-020
Date: September 10, 2026

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1.

In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2.

Tracked as CVE-2026-67277Footnote 3, this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information.

Tracked as CVE-2026-86060Footnote 5, this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88)Footnote 6 that may allow a remote attacker to escalate privileges.

Tracked as CVE-2026-67276Footnote 7, this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347)Footnote 8 that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key.

On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. Footnote 9Footnote 10

Suggested actions

The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletinFootnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions:

This is an extract. The publication continues at the source.

Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060

Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Canadian Centre for Cyber Security — imported from official source
Official source
https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-ro...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.