{"total":8,"items":[{"id":115,"title":"[NIEUW] [hoog] MikroTik RouterOS: Kwetsbaarheid maakt code-uitvoering en DoS mogelijk","original_title":"[NEU] [hoch] MikroTik RouterOS: Schwachstelle ermöglicht Codeausführung und DoS","source_rating":"hoog","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3661","type":"advisory","language":"de","published_at":"2026-09-30T11:16:29+00:00","severity":"middel","priority":25,"vendors":["MikroTik"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":78,"title":"Warning: Critical vulnerabilities in Mikrotik RouterOS, Patch immediately!","original_title":"Warning: Critical vulnerabilities in Mikrotik RouterOS, Patch immediately!","source_rating":null,"summary":"","ai":false,"actions":[],"url":"https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-mikrotik-routeros-patch-immediately","type":"advisory","language":"en","published_at":"2026-09-28T14:44:33+00:00","severity":"laag","priority":20,"vendors":["MikroTik"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ccb-be","name":"CCB / Safeonweb@work (België)","category":"overheid","country":"BE","license":"© CCB, hergebruik voorbehouden","reuse":"link"},"bundle":null},{"id":138,"title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","original_title":"CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","source_rating":null,"summary":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.\n\nVereiste actie: Apply mitigations in accord","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67279","type":"kev","language":"en","published_at":"2026-09-25T00:00:00+00:00","severity":"middel","priority":40,"vendors":["MikroTik"],"cves":[{"id":"CVE-2026-67279","cvss":6.9,"epss":0.01027,"epss_percentile":0.6236,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":6.9,"epss_max":0.01027,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":627,"title":"Case update: DIVD-2026-00012 - MikroTik RouterOS MikroTrick vulnerabilities","original_title":"Case update: DIVD-2026-00012 - MikroTik RouterOS MikroTrick vulnerabilities","source_rating":null,"summary":"Last event: 21 Sep 2026 - Created case file and notifying potential victims","ai":false,"actions":[],"url":"https://csirt.divd.nl/cases/DIVD-2026-00012/","type":"advisory","language":"en","published_at":"2026-09-21T00:00:00+00:00","severity":"laag","priority":5,"vendors":["MikroTik"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"divd","name":"DIVD CSIRT","category":"onderzoek","country":"NL","license":"© DIVD","reuse":"excerpt"},"bundle":null},{"id":159,"title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","original_title":"CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","source_rating":null,"summary":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86060","type":"kev","language":"en","published_at":"2026-09-10T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["MikroTik"],"cves":[{"id":"CVE-2026-86060","cvss":9.2,"epss":0.06392,"epss_percentile":0.93466,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.2,"epss_max":0.06392,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":160,"title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","original_title":"CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","source_rating":null,"summary":"MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67277","type":"kev","language":"en","published_at":"2026-09-10T00:00:00+00:00","severity":"hoog","priority":63,"vendors":["MikroTik"],"cves":[{"id":"CVE-2026-67277","cvss":8.8,"epss":0.0156,"epss_percentile":0.74355,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":8.8,"epss_max":0.0156,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":43,"title":"Kwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu","original_title":"Kwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu","source_rating":null,"summary":"Er zijn meerdere ernstige kwetsbaarheden gevonden in MikroTik RouterOS. Deze kwetsbaarheden worden actief misbruikt en is vooral gericht op routers met publiek toegankelijke SSH-diensten. Het NCSC adviseert om de updates van MikroTik zo snel mogelijk te installeren om risico’s te beperken.","ai":false,"actions":[],"url":"https://www.ncsc.nl/alerts/kwetsbaarheden-in-mikrotik-routeros-actief-misbruikt-update-nu","type":"news","language":"nl","published_at":"2026-09-08T12:00:32+00:00","severity":"hoog","priority":50,"vendors":["MikroTik"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ncsc-nl-nieuws","name":"NCSC-NL Nieuws & alerts","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":518,"title":"CVE-2026-67276: MikroTik RouterOS, actief misbruikt","original_title":"CVE-2026-67276: MikroTik RouterOS, actief misbruikt","source_rating":null,"summary":"RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with expon","ai":false,"actions":[],"url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-72024","type":"advisory","language":"en","published_at":"2026-09-05T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["MikroTik"],"cves":[{"id":"CVE-2026-67276","cvss":9.2,"epss":0.06451,"epss_percentile":0.93527,"in_kev":false,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.2,"epss_max":0.06451,"source_count":1,"ncsc":null,"source":{"slug":"euvd","name":"ENISA EU Vulnerability Database","category":"vulnerability","country":"EU","license":"ENISA, hergebruik met bronvermelding","reuse":"open"},"bundle":null}]}