LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 25, 2026
CVSS 6.9 · Medium⚠ Actively exploited (CISA KEV)
6.9
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
Sep 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities catalog on Sep 25, 2026, with a federal patch deadline of Sep 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CVE-2026-67279 is an improper enforcement of behavioral workflow flaw in MikroTik RouterOS. In plain terms, the product does not correctly enforce the intended order or conditions of certain session and command steps, which can let an unauthenticated client open a session channel and send an exec request. CISA notes this issue can be chained to achieve unauthenticated exploitation of CVE-2026-86060. For teams running RouterOS on edge or internal network devices, that combination raises the priority of inventory, exposure review, and timely vendor mitigations.

Public detail in the provided record does not include version ranges, CVSS scores, or exploit code. Confirm affected builds, fixed releases, and exact configuration guidance against the vendor advisory before you act on version-specific claims.

How it works

The weakness is tracked as CWE-841 (Improper Enforcement of Behavioral Workflow). Products in this class expect a defined sequence of authentication, session setup, and privileged operations. When that workflow is not enforced, a client may reach a later step—such as opening a session channel and issuing an exec-style request—without completing earlier checks that should have blocked unauthenticated use.

According to the CISA summary, an unauthenticated client may open a session channel and send an exec request. The same summary states the vulnerability can be chained so that unauthenticated exploitation of CVE-2026-86060 becomes possible. Do not assume a full remote code execution path, payload format, or default service binding from this record alone; treat chaining as a reason to treat both CVEs together in triage and to verify mechanics only from vendor and authoritative advisories.

Am I affected? How to find it in your systems

MikroTik RouterOS commonly runs on MikroTik routers, wireless devices, and related network appliances used for routing, VPN, firewalling, and remote administration. Inventory every device that reports RouterOS in asset management, network discovery, or configuration backups.

How to remediate

Patch first: apply the vendor update and mitigations named in the official MikroTik advisory for this CVE, and address CVE-2026-86060 in the same maintenance window if the vendor links them. Confirm build numbers and install steps only from that advisory.

If you can't patch immediately

Reduce reachability and monitor aggressively until vendor fixes are installed.

If your data may have been exposed

Actively exploited network-device vulnerabilities can lead to device takeover, traffic interception, lateral movement, and eventual data theft from connected systems. If you suspect compromise, isolate affected routers, preserve volatile evidence and logs, credential-rotate admin and dependent service accounts, and follow your incident response process alongside vendor and CISA triage guidance. As a supplementary check for personal or work emails tied to your organization, you can run a free exposure scan of your email against known breach datasets to see whether those addresses already appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMikroTik · RouterOS
WeaknessCWE-841
CVSS base score6.9 (Medium)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedSep 5, 2026
Added to CISA KEVSep 25, 2026
Federal patch deadlineSep 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities