Vendor

MikroTik

5 known exploited

MikroTik news

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…

Why it matters

CISA lists this as exploited in the wild. Unpatched SharePoint and RouterOS systems are exposed to active attacks now.

Patch

Apply the vendor's security update for SharePoint and RouterOS.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability (CVE-2026-67279) is being actively exploited, CISA warns

CISA added CVE-2026-67279 (MikroTik RouterOS) to its Known Exploited Vulnerabilities catalog on September 25, 2026, which means there is reliable evidence of exploitation in the wild. Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve…

Why it matters

CISA lists this as exploited in the wild. Unpatched RouterOS systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Actively exploited

All 5 →

MikroTik RouterOS

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Added Sep 25, 2026Fed. due Sep 28, 2026Coverage →

MikroTik RouterOS

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

Added Sep 10, 2026Fed. due Sep 13, 2026Coverage →

MikroTik RouterOS

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

Added Sep 10, 2026Fed. due Sep 13, 2026

MikroTik RouterOS

MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

Added Sep 8, 2022Fed. due Sep 29, 2022

MikroTik RouterOS

MikroTik Router OS Directory Traversal Vulnerability

Added Dec 1, 2021Fed. due Jun 1, 2022

Products