MikroTik RouterOS flaw added to US 'actively exploited' list — but details are thin
CISA says CVE-2026-67277 is being exploited right now, yet the public record so far tells you almost nothing about how it works or who's actually being hit.
A vulnerability in MikroTik’s RouterOS, tracked as CVE-2026-67277, has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalogue. That listing, dated 10 September 2026, is CISA’s way of saying this isn’t a theoretical risk sitting in a lab somewhere — it has confirmed evidence that someone, somewhere, is actively using this bug against real targets.
That’s the known part. What’s less clear from the public record right now is exactly how the flaw works, what an attacker needs to pull it off, or which RouterOS versions are exposed. The NVD entry exists but hasn’t yet been fleshed out with the technical detail — CVSS score, attack vector, affected builds — that usually accompanies a KEV addition. So treat the “actively exploited” label as solid, and treat everything else about the mechanics as a gap to be filled once vendor and researcher write-ups catch up.
What we actually know
MikroTik makes RouterOS, the operating system that runs on its widely used range of routers, switches and wireless gear — kit found everywhere from small ISPs and offices to hobbyist networking setups. CISA’s KEV catalogue exists specifically to flag vulnerabilities with confirmed, real-world exploitation, as opposed to the much larger pile of vulnerabilities that are merely possible to exploit in theory. Getting onto that list is a meaningful signal: it means someone has seen this used in the wild, not just modelled it.
Federal US civilian agencies have been given until 13 September 2026 to apply mitigations, under CISA’s binding operational directive covering risk-based patching. That’s a tight three-day window, which itself tells you CISA rates the exploitation as credible and ongoing rather than a one-off incident.
So who is actually at risk
Here’s the important caveat: the KEV deadline is a compliance requirement for US federal agencies. It is not a global mandate, and it doesn’t mean every RouterOS device on the planet is under active attack today. Whether ransomware groups are involved is listed as “unknown” in CISA’s own entry, so there’s no confirmed link to an extortion campaign at this stage.
That said, MikroTik gear has a track record of ending up in botnets and being scanned relentlessly by opportunistic attackers, precisely because so many devices are left running old firmware on default configurations. Anyone running RouterOS — network administrators, small ISPs, and the more technically minded home users who’ve deployed MikroTik hardware — should assume this is relevant to them, even without a US government mandate hanging over their head.
What to do about it
Because the sources here don’t spell out a specific patched version number, the sensible move is to go straight to MikroTik’s own advisories and change-log for the vulnerability, rather than wait for the wider write-up to appear. Standard hygiene applies regardless: keep RouterOS updated to the latest stable release, disable any remote management interfaces you don’t actually need, and check whether your device’s web or Winbox admin access is exposed to the open internet — a surprisingly common and avoidable mistake.
The takeaway
This is a genuine, confirmed-exploited vulnerability, not hype — but the technical picture is still filling in. If you run RouterOS, patch as soon as MikroTik’s guidance is available and lock down remote access in the meantime. If you don’t, there’s no reason for alarm; just don’t assume “actively exploited” automatically means “actively exploited against you.”