First published · Last updated
CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that can allow an unauthenticated client to open a session channel and send an exec request and can be chained to exploit CVE-2026-86060. CISA requires applying vendor mitigations and following BOD 26-04 guidance, including evaluating internet exposure or discontinuing use if mitigations are unavailable.
Categories: technology, politics-and-governance
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 7/10
- Geographic reach
- 4/10
- Global importance
- 5/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Unauthenticated exploitation is possible and CISA directs stakeholders to apply mitigations and BOD 26-04 patching guidance.

