Threat Brief — 2026-09-11 — Second MikroTik RouterOS CVE hits KEV
Executive summary: CISA has added a second MikroTik RouterOS vulnerability — CVE-2026-86060KEV — to its Known Exploited Vulnerabilities catalog, expanding an active-exploitation story that began with CVE-2026-67277KEV on 2026-09-04. Both flaws allow unauthenticated remote attackers to compromise RouterOS devices through different mechanisms. Separately, a 22-year-old Singaporean national has pleaded guilty in U.S. federal court to orchestrating a $245 million Bitcoin theft ring built on social engineering.
Top items
- MikroTik RouterOS — second CVE added to CISA KEV. CVE-2026-86060KEV, an improper neutralization of argument delimiters vulnerability in MikroTik RouterOS, is now listed in CISA's Known Exploited Vulnerabilities catalog. It allows an attacker to change the trust level of a RouterOS device. This is the second MikroTik RouterOS CVE added to KEV this month: CVE-2026-67277KEV, a missing-authentication-for-critical-function flaw enabling kernel memory disclosure and denial of service via the btest service, was first reported in KEV on 2026-09-04 by RSS:securitylab-ru. Both are known-exploited-in-the-wild; organisations with internet-exposed MikroTik devices face elevated risk. (src: CISA KEV)
- Singaporean national pleads guilty to $245M Bitcoin theft. Malone Lam, a 22-year-old Singaporean citizen, pleaded guilty on Tuesday to a U.S. federal charge of organising a criminal enterprise. According to investigators, he led an international group that used social engineering techniques to steal approximately $245 million in Bitcoin from cryptocurrency holders. The case underscores continued effectiveness of social-engineering-driven crypto theft at scale. (src: RSS:xakep)
Themes
Edge-device exploitation persists. The addition of a second MikroTik RouterOS CVE to KEV within the same week reinforces a sustained pattern of attackers targeting perimeter and networking devices — a theme also visible in recent WatchGuard Firebox and Check Point VPN disclosures.
Social engineering remains a high-yield vector. The $245M Bitcoin theft conviction is a reminder that technical sophistication is not always required; deception targeting individuals continues to produce outsized financial returns.
