DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

MikroTik RouterOS on CISA KEV: 6.49.21 Is the Only Fix for Any 6.x

CISA listed two MikroTik RouterOS flaws on September 10, 2026. CERT Polska's vulnerable range covers every 6.x build below 6.49.21, and 6.49.21 is the…

What the two catalog entries are, and what they are not

CVE What it is CVSS Vulnerable range (CERT Polska) On CISA KEV
CVE-2026-86060 SSH session privilege manipulation via a crafted username; the session ends up with full administrative rights 9.2 6.0.0 to 6.49.20; 7.0.0 to 7.23.3; 7.24 to 7.24.1 Yes, September 10
CVE-2026-67277 Bandwidth-test service accepts an unauthenticated connection into a post-login state; leaks kernel memory or restarts the router 8.8 6.0.0 to 6.49.20; 7.0.0 to 7.23.3; 7.24 to 7.24.1 Yes, September 10
CVE-2026-67276 SSH authentication bypass: RouterOS matched an RSA key by modulus alone, so a forged key with exponent one logs in without the private key 9.2 7.9 to 7.23.3; 7.24 to 7.24.1 No, as of September 10

What's covered

  • What the two catalog entries are, and what they are not
  • Every RouterOS line against the fix list
  • What to do, by line

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-mikrotik-routeros-cve-2026-86060-only-6-49-21-fixed

Top comments (0)