Two MikroTik RouterOS flaws chain into pre-authentication remote code execution
On September 10, 2026, CISA added two MikroTik RouterOS flaws — a missing authentication check and a command injection — to its KEV catalog after active exploitation. The chain yields remote code execution with no credentials, and the federal remediation deadline lands on September 13.