CISA Adds Critical Pre-Auth RCE Vulnerability in MikroTik RouterOS to KEV Catalog
Emergency directive issued for federal agencies; active exploitation confirmed prior to advisory

Key Takeaways
- CISA has added the MikroTik RouterOS vulnerability to its KEV catalog, requiring federal agencies to patch.
- The flaw is a pre-authentication remote code execution vulnerability allowing remote compromise without credentials.
- Active exploitation was confirmed prior to the CISA advisory.
- MikroTik has released RouterOS versions 7.12.3 and 7.13.1rc containing the fix.
- Private sector and other organizations are strongly advised to update affected systems immediately.
Quick answers
- What happened?
- CISA has added a critical pre-authentication remote code execution vulnerability in MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, mandating patching for U.S. federal civilian executive branch agencies. The flaw allows remote attackers to execute arbitrary code or cause denial-of-service without authentication. MikroTik has released patched versions 7.12.3 and 7.13.1rc to address the vulnerability.
- Which products are affected?
- RouterOS
- What should defenders do?
- Update MikroTik RouterOS to version 7.12.3 (stable) or 7.13.1rc (release candidate) immediately. CISA requires federal agencies to patch by the mandated deadline. Network segmentation and monitoring for suspicious router activity are recommended while patches are applied.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, issuing an emergency directive requiring federal agencies to patch affected systems. The vulnerability is a pre-authentication remote code execution (RCE) flaw in RouterOS that could allow remote attackers to execute arbitrary code or cause denial-of-service conditions without requiring credentials.
MikroTik has addressed the flaw by releasing RouterOS version 7.12.3 (stable) and 7.13.1rc (release candidate). CISA's directive mandates that federal civilian executive branch agencies update to these patched versions by a specified deadline. The agency noted that the vulnerability was reported as actively exploited in the wild prior to the advisory release.
Security researchers and CISA confirmed that the vulnerability was being actively weaponized before the official advisory, consistent with the pre-auth RCE vector that allows compromise without user interaction or credentials. The KEV catalog addition triggers mandatory remediation timelines for affected government systems.
Security Details
The vulnerability affects MikroTik RouterOS and allows pre-authentication remote code execution or denial-of-service. Successful exploitation could lead to full device compromise, lateral movement into internal networks, data exfiltration, and service disruption. The flaw was reported as actively exploited in the wild prior to the CISA advisory.
Affected products
RouterOS
Mitigation
Update MikroTik RouterOS to version 7.12.3 (stable) or 7.13.1rc (release candidate) immediately. CISA requires federal agencies to patch by the mandated deadline. Network segmentation and monitoring for suspicious router activity are recommended while patches are applied.
Sources
BleepingComputer
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Sep 30, 2026 · 15:49
Original link
Related Security News

Cisco Advises Urgent Patching of Critical Authentication Bypass in SD-WAN Manager
Cisco has confirmed that a critical vulnerability in Catalyst SD-WAN Manager is being actively exploited. The flaw, tracked as CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and Cisco states there is no workaround. The advisory was published on September 30, 2026.

