MikroTik RouterOS bug added to US 'actively exploited' list — but details are thin on the ground

CISA says attackers are already using this router flaw in the wild, yet the public record says almost nothing about how it actually works.

Silver and black combination lock
Photo · Nicolas HIPPERT / Unsplash

What’s actually confirmed

CISA has added a MikroTik RouterOS flaw, tracked as CVE-2026-67279, to its Known Exploited Vulnerabilities catalogue on 25 September 2026. That listing matters because CISA only puts a bug in the KEV catalogue when it has evidence — not theory — that someone is actually using it against real targets. US federal civilian agencies have been given until 28 September 2026 to patch or mitigate, a three-day turnaround that signals CISA views this as urgent rather than routine.

Beyond that, the record is unusually sparse. There’s no CVSS score published in the entry we’ve seen, no description of the vulnerability class (is it a buffer overflow, an authentication bypass, a command injection?), no list of affected RouterOS versions, and no detail on the attack path — whether exploitation requires network access, valid credentials, or nothing more than reaching an exposed web interface. CISA’s own guidance simply points administrators towards “vendor instructions” and its general BOD 26-04 patching directive, without spelling out what those instructions actually are.

So who is actually at risk

RouterOS runs on MikroTik’s range of routers, switches and wireless gear, which are popular with ISPs, small businesses and networking hobbyists rather than being embedded in typical consumer broadband routers from the likes of BT or Virgin Media. If you’ve never heard of MikroTik, you almost certainly aren’t running it.

The three-day compliance deadline applies only to US federal agencies — it is not a global mandate, and UK organisations are under no legal obligation to act by that date. That said, CISA’s KEV catalogue is watched closely by security teams everywhere precisely because it flags vulnerabilities under live attack, and MikroTik devices have a long history of being scooped up into botnets (Mēris being the best-known example) once a flaw goes public. Anyone running RouterOS on internet-facing infrastructure — ISPs, hosting providers, small offices with MikroTik edge routers — should treat this as relevant regardless of geography.

What to do about it

Given the limited detail available, the sensible move is the boring one: check MikroTik’s own advisories and changelog for RouterOS updates referencing this CVE, and apply whatever patch or configuration mitigation the vendor publishes. If your device’s web or API management interface is exposed directly to the internet — something MikroTik gear is sometimes configured to do by default or through lazy setup — locking that down or putting it behind a VPN is worthwhile even before a patch lands.

For everyone else, this isn’t a story about your home Wi-Fi. It’s a reminder that “actively exploited” is a serious label CISA doesn’t hand out casually, but the label alone doesn’t tell you how bad the bug is, how it’s being exploited, or how easy it is to fix — those details simply aren’t public yet. Network administrators running MikroTik kit should go looking for vendor guidance now rather than waiting for a fuller writeup; the rest of us can file this under “watch this space” rather than “panic”.

Sources