CISA Warns of Active Exploitation of Two MikroTik RouterOS Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities affecting MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) Catalog. One flaw involves a missing authentication check on a critical function, while the other allows attackers to manipulate command arguments in ways that were not intended. Both are confirmed to be actively exploited by cyber criminals.
MikroTik routers are widely used by small businesses and internet service providers for networking and internet gateway functions. Vulnerabilities like these can allow attackers to gain unauthorised control over network devices, potentially exposing internal systems, intercepting traffic, or using the device as a foothold for further attacks.
While CISA's directive requiring rapid remediation officially applies only to US federal agencies, the agency strongly encourages all organisations, including Australian businesses, to treat KEV-listed vulnerabilities as high priority. Any business running MikroTik RouterOS devices should check for available firmware updates and apply them without delay.