CISA Adds MikroTik RouterOS Flaws CVE-2026-67277 and CVE-2026-86060 to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities affecting MikroTik RouterOS to its Known Exploited Vulnerabilities Catalog.
The first issue, CVE-2026-86060, arises from insufficient sanitization of command argument delimiters. Exploitation requires an attacker to reach the SSH login helper within an established session; once there, the attacker can modify trusted RouterOS policy masks, resulting in privilege escalation.
The second vulnerability, CVE-2026-67277, stems from missing authentication in critical RouterOS functions. An unauthenticated attacker can establish a connection before authentication completes, potentially disclosing kernel memory contents or triggering denial-of-service conditions.
CISA instructed US federal agencies to remediate both flaws no later than September 13 and to investigate any evidence of compromise associated with CVE-2026-86060. The agency warned that the vulnerabilities are likely to see wider exploitation and advised all organizations running affected MikroTik products to review their exposure.
Related articles
Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws
The Apache WSS4J library, used to apply WS-Security to SOAP messages in Java environments, has received updates fixing seven vulnerabilities. The development team disclosed multiple security advisories on September 30, 2026, covering the issues. Three vulnerabilities received an Important severity rating: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616. CVE-2026-88920 allows authentication bypass in the DOM security processor by injecting attacker-controlled keys into crafted unsigned sender-vouches SAML assertions. CVE-2026-89238 stems from improper handling of encryption headers, enabling attackers to force plaintext elements to be treated as decrypted headers and bypass security policies. The remaining four vulnerabilities were also resolved in the same coordinated update release.
US Authorities Warn of Active Exploitation of Apple CoreGraphics and Cisco SD-WAN Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two newly identified vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-86950 affects Apple iOS, iPadOS, and macOS through a flaw in the CoreGraphics framework that allows out-of-bounds memory writes and potential arbitrary code execution. CVE-2026-76504 impacts Cisco Catalyst SD-WAN Manager, enabling unauthenticated attackers to gain administrative access due to improper URI encoding handling in the API. Federal agencies must remediate both issues within three days of their respective catalog additions. CISA also requires organizations to check for signs of compromise in addition to applying patches. The alerts highlight ongoing risks to widely deployed Apple operating systems and enterprise SD-WAN infrastructure.
Cisco Patches Critical Zero-Day Authentication Bypass in Catalyst SD-WAN Manager
Cisco Systems has released security updates to address a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows attackers to bypass authentication and gain remote administrator access. The flaw, tracked as CVE-2026-76504, stems from improper URI encoding handling in HTTP requests targeting specific APIs. With a CVSS v3.1 base score of 9.8, the issue is rated Critical and has already been exploited in real-world attacks confirmed by Cisco in September 2026. The company published its security advisory on September 30, 2026, and strongly recommends immediate updates to the fixed releases. Organizations are also advised to restrict API access to trusted sources while applying the patches.
Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement
Two critical zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild to achieve unauthenticated remote code execution. Attackers deploy password-protected PHP web shells such as WHIPSHOT and use the Python-based SLAPSHOT tunneling tool for lateral movement inside targeted networks. The flaws affect NetScaler ADC and NetScaler Gateway appliances with default configurations, and one requires DTLS enabled on VPN vServers. Citrix has released patches for versions 13.1-64.23 and 14.1-73.37, while CISA added the issues to its KEV catalog with a September 30, 2026 remediation deadline for U.S. federal agencies. Organizations are advised to hunt for indicators including modified httpd.conf entries, anomalous setuid permissions on /bin/sh, and suspicious files in /var/netscaler/logon/LogonPoint/custom before applying updates.