Mark RadarMARK RADAR
About
EN
Sign in

CISA Warns of Actively Exploited MikroTik RouterOS Flaws

2 reports · First detected 2026-09-11 · Last active 2026-09-15

MikroTik’s RouterOS powers networking equipment used by businesses, internet providers and other organizations, making vulnerabilities in the platform a potentially broad security risk. Poland’s CERT Polska used artificial intelligence to help uncover multiple RouterOS weaknesses and reported that some had already been exploited in real-world attacks, raising the urgency for administrators to update exposed devices before attackers can gain access or interfere with network traffic.

The U.S. Cybersecurity and Infrastructure Security Agency added two actively exploited MikroTik flaws to its Known Exploited Vulnerabilities catalog and ordered federal agencies to complete remediation by Sept. 13. The warning came as the Shadowserver Foundation identified about 2.6 million MikroTik routers exposed to the internet worldwide, including nearly 19,000 in Taiwan. The figures do not establish that every exposed device is vulnerable, but they illustrate the scale of the potential attack surface.

All Coverage

2 original reports

The Backstory

The history behind this event
CISA Flags Seven Actively Exploited Flaws Across AI and Enterprise Systemsfirst seen 2026-09-03 · 1 reports · similarity 0.76 · same topic: U.S. Cybersecurity and Infrastructure Security Agency (CISA)

The Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog identifies flaws backed by evidence of real-world attacks, making them a priority for remediation. The latest warning spans firewalls, software-development infrastructure and AI control points. Gateways such as LiteLLM can hold model-provider keys, database connections and routing credentials, raising the risk that an initial breach could lead to secret theft, persistent access and abuse of computing resources.

CISA added seven vulnerabilities on Sept. 2, 2026: two affecting SonicWall SMA1000 appliances and one each in Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra OSS and BerriAI LiteLLM. The Kestra command-injection flaw and SonicWall server-side request forgery carry CVSS scores of 10.0. US federal agencies face a Sept. 5 deadline for five of the flaws, while remediation of the Starlette and LiteLLM vulnerabilities is due by Sept. 16.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)