Planet Briefing

First published · Last updated

CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that can allow an unauthenticated client to open a session channel and send an exec request and can be chained to exploit CVE-2026-86060. CISA requires applying vendor mitigations and following BOD 26-04 guidance, including evaluating internet exposure or discontinuing use if mitigations are unavailable.

Categories: technology, politics-and-governance

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
7/10
Geographic reach
4/10
Global importance
5/10
Impact magnitude
4/10
Positivity
2/10
Urgency
6/10

Why it matters

Unauthenticated exploitation is possible and CISA directs stakeholders to apply mitigations and BOD 26-04 patching guidance.

Location

Sources

Report an issue