CISA added two actively exploited MikroTik RouterOS vulnerabilities to the KEV Catalog: a missing-authentication flaw and a command-injection flaw, both enabling device takeover. Two MikroTik RouterOS vulnerabilities are under active exploitation: CVE-2026-67277 (missing authentication for a critical function) and CVE-2026-86060 (command argument delimiter injection). Both allow unauthenticated attackers to gain control of affected routers. CISA requires FCEB agencies to remediate per BOD 26-04 and urges all organizations to patch immediately.
missing-authentication
4 posts
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-67277, CVE-2026-86060) Tycon Systems TPDIN-Monitor-WEB2 (Update A) (CVE-2026-61884, CVE-2026-55985) Tycon Systems TPDIN-Monitor-WEB2 (Update A) devices running firmware prior to 2.4.5 contain two vulnerabilities: a critical missing authentication flaw (CVE-2026-61884, CVSS 9.8) that exposes the web management interface without login on unconfigured units, and a medium-severity cleartext credential storage issue (CVE-2026-55985). An attacker with network access to an unconfigured device can manipulate power relays and physical equipment, posing a safety risk. Firmware 2.4.5 resolves both issues.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-81578, CVE-2026-82078) CISA added two actively exploited vulnerabilities affecting PaperCut NG/MF to its Known Exploited Vulnerabilities Catalog. CVE-2026-81578 is a missing authentication for critical function vulnerability and CVE-2026-82078 is an unsafe reflection vulnerability. Federal agencies are required to remediate these under BOD 26-04, and CISA recommends all organizations prioritize patching.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-72529, CVE-2026-72530) CISA added two actively exploited TrueConf Server vulnerabilities to the KEV Catalog: CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection). Federal agencies are required by BOD 26-04 to remediate these on publicly exposed assets. CISA recommends all organizations prioritize patching these vulnerabilities.