Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.
Dataset Summary
| Field | Value | Interpretation |
|---|---|---|
| Reporting Period | September 2–10, 2026 | From the earliest dated attack observation used here to KEV inclusion. The catalog due dates are September 13; source review was completed September 25, 2026. |
| Data Sources | Supplied CVE list; CISA KEV; official CVE records; RouterOS advisory and release notices; public exploitation reporting | The supplied list defines the two-CVE scope. External primary sources provide the additional chronology, version details, and exploitation context. |
| Total CVEs Analyzed | Two | CVE-2026-86060 and CVE-2026-67277, both affecting MikroTik RouterOS. |
| Average Vendor-Advisory-to-Patch Gap | 0 calendar days | The vendor notice and the stable/long-term releases used here are dated September 3. This is not a measure of when exploitation began. |
| Average CVE-Publication-to-Patch Gap | −2 calendar days | The September 3 production fixes preceded the September 5 CVE publications by two days. The negative value reflects the selected date fields, not negative remediation time. |
| Average / Median Patch-to-KEV Gap | 7 days / 7 days | Both CVEs share the same production-release and KEV dates. |
| Shortest / Longest Patch-to-KEV Gap | 7 days / 7 days | Both records are tied; there is no timing outlier in this two-CVE sample. |
| Average Patch-to-First-Exploitation Gap | Unavailable | One case has a dated exploitation bound, not a proven first-ever attack day; the other has no dated observation. A full-cohort average is unsupported. |
| Confirmed Pre-Production-Patch Exploitation | CVE-2026-86060: at least 1 calendar day | SSH-chain attacks were observed from at least September 2, before the September 3 production fixes. No equivalent dated interval is established for CVE-2026-67277. |
| KEV-to-Due-Date Interval | 3 calendar days for both | September 10 to September 13. These are recorded catalog dates, not an attacker-free period. |
Sourcing and Methodology Note
The analysis retains both entries from the supplied list without adding other vulnerabilities to the statistical dataset. The CISA alert CISA Adds Two Known Exploited Vulnerabilities to Catalog, dated September 10, 2026, confirms the selection and states that inclusion is based on evidence of active exploitation. The KEV catalog, version 2026.09.24, supplies the addition dates, remediation deadlines, forensic-triage flags, and ransomware-use fields. The alert and BOD 26-04, Prioritizing Security Updates Based on Risk, provide the federal-scope context.
Patch availability is established from the September 3, 2026 RouterOS release announcements for 6.49.21, 7.23.4, and 7.24.2, with the fix association corroborated by the September 2026 vulnerability advisory and the official CVE descriptions. The technical disclosure Vulnerabilities in Mikrotik RouterOS software, dated September 5, 2026, supports the branch-specific affected ranges and technical descriptions. These are historical fixed-release thresholds, not a claim that those builds are the latest releases.
CVE publication dates, descriptions, explicit affected-version lists, CWE classifications, and CVSS v4.0 metrics come from the CVE Program records for CVE-2026-86060 and CVE-2026-67277. The version-data discrepancy discussed below is retained from the affected-version, CPE applicability, and description fields in the CVE-2026-67277 record rather than resolved by assumption.
Introduction
Successful RouterOS SSH-chain attacks were documented from at least September 2, before the September 3 production fixes. The in-scope CVE involved is CVE-2026-86060. Both selected CVEs then entered KEV seven days after the production releases, demonstrating why patch-to-KEV timing cannot stand in for the start of exploitation.
The one-day pre-production-patch interval is a minimum supported by the dated observation, not a proven total attack duration. The other entry, CVE-2026-67277, lacks a comparable dated observation. Separately, the limited-detail vendor warning appeared with the fixes, while the CVE-specific publications followed two days later.
Background and Context
CVE-2026-86060 concerns argument handling in the SSH login path. A crafted username can alter the trusted RouterOS policy mask and escalate privileges. The CVE description specifies that an unauthenticated SSH session must reach the login helper; the flaw should not be reduced to a generic web-interface command-injection claim.
CVE-2026-67277 affects the bandwidth-test service, also called btest. Its authentication-state handling can permit an unauthenticated client to reach functionality that exposes kernel memory or causes a kernel restart. Those are the documented effects of this CVE; they do not, by themselves, establish arbitrary code execution or complete device takeover.
The vendor advisory names production fixes in 6.49.21, 7.23.4, and 7.24.2, and also lists the development build 7.25beta3. This article's patch date refers specifically to the three stable/long-term releases, not to a reconstructed earliest release across every development build. The initial announcement deliberately withheld technical detail to allow time for updates.
Gap Calculation Methodology
The vendor advisory date (A), CVE publication date (D), production patch date (P), actual first-exploitation date (E), and KEV addition date (K) are separate events. B is a date by which exploitation is known to have occurred, even when E is unknown. The catalog due date is R.
Vendor-Advisory-to-Patch Gap = P − A
CVE-Publication-to-Patch Gap = P − D
Patch-to-KEV Gap = K − P
Patch-to-First-Exploitation Gap = E − P
Minimum Pre-Patch Lead = P − B, where E is on or before B
Catalog Remediation Interval = R − K
For both records, A and P are September 3, D is September 5, K is September 10, and R is September 13, 2026. The release notices date 6.49.21, 7.23.4, and 7.24.2, each identified as fixing both CVEs. For the documented SSH-chain activity, B is September 2: P − B is one day, and the actual pre-patch lead may be longer. B is unavailable for the bandwidth-test case.
Differences use calendar dates without inclusive counting. A same-day value does not determine the intraday sequence. The −2-day CVE-publication-to-patch result does not mean there was no earlier public notice: the vendor advisory was already available on September 3. Similarly, a security-assessment timestamp is not an observed attack date.
Patch Timeline & Exploitation Gap Analysis
The patch-to-KEV distribution is [7, 7] calendar days, giving a mean and median of seven days. Because the entries share a release event, these are two CVE-level observations of one update cycle, not two independent tests of patch responsiveness.
| Calculated Metric | CVE-2026-86060 | CVE-2026-67277 | Cohort Result |
|---|---|---|---|
| Vendor advisory → production patch | 0 days | 0 days | Mean 0; median 0 |
| CVE publication → production patch | −2 days | −2 days | Mean −2; median −2 |
| Production patch → KEV addition | 7 days | 7 days | Mean 7; median 7 |
| CVE publication → KEV addition | 5 days | 5 days | Mean 5; median 5 |
| Observed-exploitation-to-production-patch lead | At least 1 day | Unavailable | No full-cohort mean or median |
| Production patch → actual first exploitation | No exact value; at most −1 day | Unavailable | Not calculated |
Changing the starting event changes the result: the five-day publication-to-KEV gap is not interchangeable with the seven-day patch-to-KEV gap. Neither value measures an organization's actual patch deployment delay. That would require installation records, which are not part of this dataset.
CVE Timeline Data
The table retains the earlier advisory and later CVE publication as separate events. “Patch available” refers to the production releases defined above. A dated attack observation supplies a bound; a report date or KEV date is not substituted for the actual start of exploitation.
| CVE ID | Vendor Advisory / CVE Publication | Production Patch Available | First Observed Exploitation | KEV Added | Days: Advisory → Patch | Days: Patch → KEV | CISA Due Date |
|---|---|---|---|---|---|---|---|
| CVE-2026-86060 | September 3 / September 5, 2026 | September 3, 2026 | Attacks observed from at least September 2, 2026. The true first occurrence may be earlier. | September 10, 2026 | 0 | 7 | September 13, 2026 |
| CVE-2026-67277 | September 3 / September 5, 2026 | September 3, 2026 | Exact date unavailable. KEV confirms known exploitation. | September 10, 2026 | 0 | 7 | September 13, 2026 |
Affected branches and documented production fixes
| Scope | Published Affected Range | Documented Fixed Release | Release Date |
|---|---|---|---|
| Both CVEs: RouterOS 6.x | 6.0.0 up to, but not including, 6.49.21 | 6.49.21 (long-term) | September 3, 2026 |
| Both CVEs: earlier RouterOS 7.x range | 7.0.0 up to, but not including, 7.23.4 | 7.23.4 (long-term) | September 3, 2026 |
| Both CVEs: RouterOS 7.24 range | 7.24 up to, but not including, 7.24.2 | 7.24.2 (stable) | September 3, 2026 |
Version-data discrepancy: the CVE-2026-67277 record also contains a CPE applicability range from 0.0.0 to below 7.25.1, conflicting with its explicit affected-version list and named fixes. The table above reproduces the explicit branch ranges corroborated by the dated disclosure and vendor guidance. The conflicting CPE field is not silently substituted for them.
Statistical Distribution and Outliers
Both patch-to-KEV observations are seven days, so the range is zero and neither CVE is a timing outlier. The equality of the mean and median describes this shared schedule; it does not establish a typical RouterOS or industry-wide exploitation window.
The exploitation evidence has a different shape: one in-scope case has a minimum pre-production-patch lead, while the other lacks a dated observation. There is no defensible two-CVE average for that metric. The −2-day publication-to-patch values also describe a separate event pair and must not be mistaken for an exploitation duration.
Vulnerability Class Breakdown
| CVE | Affected Function | Vulnerability Class | CWE | Published Severity |
|---|---|---|---|---|
| CVE-2026-86060 | SSH login handling | Improper neutralization of argument delimiters; privilege escalation | CWE-88 | Critical — CVSS v4.0 9.2 |
| CVE-2026-67277 | Bandwidth-test service | Missing authentication for a critical function; kernel memory disclosure and denial of service | CWE-306 | High — CVSS v4.0 8.8 |
There is only one example of each weakness class. Their matching release and catalog dates cannot support a conclusion that argument-handling and missing-authentication vulnerabilities generally have the same exploitation timing. The common schedule is the observable finding; a class-level trend is not.
Notable Case Highlights
CVE-2026-86060: keep SSH-chain evidence within its documented scope
The public report pairs CVE-2026-86060 with CVE-2026-67276, an SSH authentication-bypass issue outside the dataset. Its dated observation establishes exploitation before the production releases. It does not establish the true earliest attack or the full duration of the campaign.
Importantly, the two CVEs selected for this post are not the reported two-part SSH chain. The bandwidth-test CVE must not be substituted for the separately identified SSH authentication-bypass vulnerability.
CVE-2026-67277: a separate exposure path with the same patch dates
The bandwidth-test issue illustrates why identical chronology does not imply identical impact. The published technical description identifies premature acceptance of a related connection, leakage of uninitialized packet-buffer data, and a size-validation flaw capable of restarting the kernel. CISA's entry establishes known exploitation, but the reviewed record does not date its first occurrence.
Historical Trend Comparison
The preceding September 9 post in this series emphasized disclosure-to-KEV intervals across a different cohort. This article distinguishes a bounded pre-production-patch exploitation finding from its shared patch-to-KEV interval. Those measures cannot be compared directly to declare that exploitation is accelerating or that the gap is widening.
A meaningful series comparison would retain the same event definitions and distinguish CVE-level counts from shared release events. With only two entries from one product update cycle, this post describes a specific chronology rather than a broader trend.
MITRE ATT&CK Mapping
One limited behavioral mapping is supported. It is an analytical interpretation of reported SSH-chain activity, not a mapping inferred merely from a CWE or applied to both CVEs.
| Tactic | Technique | Evidence and Scope |
|---|---|---|
| Persistence | T1136.001 — Create Account: Local Account | The SSH-chain report documents unauthorized account creation, including a highly privileged account named ops. This supports a local-account mapping for that reported activity, not for CVE-2026-67277. |
No cohort-wide sequence covering initial access, execution, persistence, and command and control is assigned. Additional mappings would require additional attributable behavior.
Risk Context for Organizations
The operational lesson is not that defenders had seven safe days. It is that fixes were available before the formal KEV signal. An organization that waits for catalog inclusion before reviewing an explicit vendor security update can delay its response without evidence that the intervening period is safe.
The catalog preserves a three-day due-date interval for both entries, but its forensic-triage flags differ:
| CVE | Catalog Due Date | Forensic-Triage Flag | Known Ransomware Campaign Use |
|---|---|---|---|
| CVE-2026-86060 | September 13, 2026 | Yes | Unknown |
| CVE-2026-67277 | September 13, 2026 | No | Unknown |
A “No” triage flag is not evidence that a device is uncompromised, and “Unknown” ransomware use is not a confirmed absence of ransomware activity. Both recorded due dates had passed by the September 25 source-review date.
CISA's September 10 alert places federal requirements under BOD 26-04 and identifies Federal Civilian Executive Branch agencies as its scope. Other organizations should apply their own risk and compliance requirements rather than treat a catalog date as a universal legal deadline. Exposure and evidence of compromise remain relevant regardless of that distinction.
Detection and Patch Prioritization Considerations
- Confirm the branch as well as the version. Match each device to the affected ranges and documented production fixes above. Resolve inconsistent version data against the explicit advisory and CVE descriptions instead of applying a single unqualified “older than” check across all branches.
- Review exposed services separately. Assess SSH reachability for the login-path issue and bandwidth-test reachability for the separate
btestvulnerability. MikroTik's advisory recommends keeping SSH away from untrusted networks and restricting management access. - Treat patching and compromise review as separate tasks. After upgrading, inspect unfamiliar users, scripts, and configuration changes. The vendor explicitly recommends this review even when RouterOS is not marked
Flagged. - Investigate the Flagged state before clearing it. The RouterOS device-mode documentation says to assume compromise when flagged, audit the configuration, and change system passwords after the audit. Simply removing the warning is not equivalent to establishing a trusted state.
- Record actual completion. Preserve the installed version, relevant exposure changes, review findings, and any unresolved exceptions. A release announcement or a successful download is not evidence that every device has been remediated.
Key Takeaways
- The two CVEs share a seven-day production-patch-to-KEV gap, with a mean and median of seven days.
- The vendor advisory and production releases precede the CVE publications; these are distinct events and must remain distinct date fields.
- The SSH case has a minimum one-day pre-production-patch exploitation lead; the bandwidth-test case has no equivalent dated interval.
- Shared release dates do not establish a shared attack chain or an industry-wide timing pattern.
- Version validation, service-exposure review, and compromise assessment answer different questions; none should be treated as a substitute for the others.
Conclusion
This cohort combines an identical patch-to-KEV interval with unequal exploitation evidence. A dated attack observation establishes a minimum pre-production-patch lead for the SSH case; the bandwidth-test case remains undated. The shared catalog schedule does not erase that distinction.
For ongoing patch and compliance monitoring, retain attack observations, release dates, CVE publications, and catalog additions separately, then verify the deployed device. A bounded pre-patch finding is more useful than an invented exact duration, just as a release date is not proof that prior compromise has been removed.
Constantly Fix Risks with Saner Patch Management
Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.
The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.
Experience the fastest and most accurate patching software here.



