Meldingen
8 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
- 25middel
- 20laag
CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Vereiste actie: Apply mitigations in accord
40middelCase update: DIVD-2026-00012 - MikroTik RouterOS MikroTrick vulnerabilities
Last event: 21 Sep 2026 - Created case file and notifying potential victims
5laagCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-
55hoogCVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas
63hoogKwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu
Er zijn meerdere ernstige kwetsbaarheden gevonden in MikroTik RouterOS. Deze kwetsbaarheden worden actief misbruikt en is vooral gericht op routers met publiek toegankelijke SSH-diensten. Het NCSC adviseert om de updates van MikroTik zo snel mogelijk te installeren om risico’s te beperken.
50hoogCVE-2026-67276: MikroTik RouterOS, actief misbruikt
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with expon
55hoog