CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities, CVE-2026-67277 and CVE-2026-86060, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Both vulnerabilities affect MikroTik RouterOS. These types of vulnerabilities are common attack vectors for cybercriminals. Federal Civilian Executive Branch (FCEB) agencies are required by Binding Operational Directive (BOD) 26-04 to prioritize remediation of vulnerabilities listed in the KEV Catalog on publicly exposed assets. BOD 26-04 emphasizes rapid patching of high-risk vulnerabilities that grant total control post-exploitation. The directive also sets expectations for agencies to check for compromises before applying patches. While BOD 26-04 is specific to FCEB agencies, CISA urges all organizations to adopt similar risk-based vulnerability management. CISA will continue to add qualifying vulnerabilities to the KEV Catalog. Organizations can nominate exploited vulnerabilities not yet on the catalog for review. A nomination requires a CVE ID, evidence of exploitation, and clear mitigation steps.