SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026By Emandi Srinivas

Dataset Summary

FieldValueInterpretation
Reporting PeriodSeptember 2–10, 2026From the earliest dated attack observation used here to KEV inclusion. The catalog due dates are September 13; source review was completed September 25, 2026.
Data SourcesSupplied CVE list; CISA KEV; official CVE records; RouterOS advisory and release notices; public exploitation reportingThe supplied list defines the two-CVE scope. External primary sources provide the additional chronology, version details, and exploitation context.
Total CVEs AnalyzedTwoCVE-2026-86060 and CVE-2026-67277, both affecting MikroTik RouterOS.
Average Vendor-Advisory-to-Patch Gap0 calendar daysThe vendor notice and the stable/long-term releases used here are dated September 3. This is not a measure of when exploitation began.
Average CVE-Publication-to-Patch Gap−2 calendar daysThe September 3 production fixes preceded the September 5 CVE publications by two days. The negative value reflects the selected date fields, not negative remediation time.
Average / Median Patch-to-KEV Gap7 days / 7 daysBoth CVEs share the same production-release and KEV dates.
Shortest / Longest Patch-to-KEV Gap7 days / 7 daysBoth records are tied; there is no timing outlier in this two-CVE sample.
Average Patch-to-First-Exploitation GapUnavailableOne case has a dated exploitation bound, not a proven first-ever attack day; the other has no dated observation. A full-cohort average is unsupported.
Confirmed Pre-Production-Patch ExploitationCVE-2026-86060: at least 1 calendar daySSH-chain attacks were observed from at least September 2, before the September 3 production fixes. No equivalent dated interval is established for CVE-2026-67277.
KEV-to-Due-Date Interval3 calendar days for bothSeptember 10 to September 13. These are recorded catalog dates, not an attacker-free period.

Sourcing and Methodology Note

The analysis retains both entries from the supplied list without adding other vulnerabilities to the statistical dataset. The CISA alert CISA Adds Two Known Exploited Vulnerabilities to Catalog, dated September 10, 2026, confirms the selection and states that inclusion is based on evidence of active exploitation. The KEV catalog, version 2026.09.24, supplies the addition dates, remediation deadlines, forensic-triage flags, and ransomware-use fields. The alert and BOD 26-04, Prioritizing Security Updates Based on Risk, provide the federal-scope context.

Patch availability is established from the September 3, 2026 RouterOS release announcements for 6.49.21, 7.23.4, and 7.24.2, with the fix association corroborated by the September 2026 vulnerability advisory and the official CVE descriptions. The technical disclosure Vulnerabilities in Mikrotik RouterOS software, dated September 5, 2026, supports the branch-specific affected ranges and technical descriptions. These are historical fixed-release thresholds, not a claim that those builds are the latest releases.

CVE publication dates, descriptions, explicit affected-version lists, CWE classifications, and CVSS v4.0 metrics come from the CVE Program records for CVE-2026-86060 and CVE-2026-67277. The version-data discrepancy discussed below is retained from the affected-version, CPE applicability, and description fields in the CVE-2026-67277 record rather than resolved by assumption.

Introduction

Successful RouterOS SSH-chain attacks were documented from at least September 2, before the September 3 production fixes. The in-scope CVE involved is CVE-2026-86060. Both selected CVEs then entered KEV seven days after the production releases, demonstrating why patch-to-KEV timing cannot stand in for the start of exploitation.

The one-day pre-production-patch interval is a minimum supported by the dated observation, not a proven total attack duration. The other entry, CVE-2026-67277, lacks a comparable dated observation. Separately, the limited-detail vendor warning appeared with the fixes, while the CVE-specific publications followed two days later.

Background and Context

CVE-2026-86060 concerns argument handling in the SSH login path. A crafted username can alter the trusted RouterOS policy mask and escalate privileges. The CVE description specifies that an unauthenticated SSH session must reach the login helper; the flaw should not be reduced to a generic web-interface command-injection claim.

CVE-2026-67277 affects the bandwidth-test service, also called btest. Its authentication-state handling can permit an unauthenticated client to reach functionality that exposes kernel memory or causes a kernel restart. Those are the documented effects of this CVE; they do not, by themselves, establish arbitrary code execution or complete device takeover.

The vendor advisory names production fixes in 6.49.21, 7.23.4, and 7.24.2, and also lists the development build 7.25beta3. This article's patch date refers specifically to the three stable/long-term releases, not to a reconstructed earliest release across every development build. The initial announcement deliberately withheld technical detail to allow time for updates.

Gap Calculation Methodology

The vendor advisory date (A), CVE publication date (D), production patch date (P), actual first-exploitation date (E), and KEV addition date (K) are separate events. B is a date by which exploitation is known to have occurred, even when E is unknown. The catalog due date is R.

Vendor-Advisory-to-Patch Gap = P − A

CVE-Publication-to-Patch Gap = P − D

Patch-to-KEV Gap = K − P

Patch-to-First-Exploitation Gap = E − P

Minimum Pre-Patch Lead = P − B, where E is on or before B

Catalog Remediation Interval = R − K

For both records, A and P are September 3, D is September 5, K is September 10, and R is September 13, 2026. The release notices date 6.49.21, 7.23.4, and 7.24.2, each identified as fixing both CVEs. For the documented SSH-chain activity, B is September 2: P − B is one day, and the actual pre-patch lead may be longer. B is unavailable for the bandwidth-test case.

Differences use calendar dates without inclusive counting. A same-day value does not determine the intraday sequence. The −2-day CVE-publication-to-patch result does not mean there was no earlier public notice: the vendor advisory was already available on September 3. Similarly, a security-assessment timestamp is not an observed attack date.

Patch Timeline & Exploitation Gap Analysis

The patch-to-KEV distribution is [7, 7] calendar days, giving a mean and median of seven days. Because the entries share a release event, these are two CVE-level observations of one update cycle, not two independent tests of patch responsiveness.

Calculated MetricCVE-2026-86060CVE-2026-67277Cohort Result
Vendor advisory → production patch0 days0 daysMean 0; median 0
CVE publication → production patch−2 days−2 daysMean −2; median −2
Production patch → KEV addition7 days7 daysMean 7; median 7
CVE publication → KEV addition5 days5 daysMean 5; median 5
Observed-exploitation-to-production-patch leadAt least 1 dayUnavailableNo full-cohort mean or median
Production patch → actual first exploitationNo exact value; at most −1 dayUnavailableNot calculated

Changing the starting event changes the result: the five-day publication-to-KEV gap is not interchangeable with the seven-day patch-to-KEV gap. Neither value measures an organization's actual patch deployment delay. That would require installation records, which are not part of this dataset.

CVE Timeline Data

The table retains the earlier advisory and later CVE publication as separate events. “Patch available” refers to the production releases defined above. A dated attack observation supplies a bound; a report date or KEV date is not substituted for the actual start of exploitation.

CVE IDVendor Advisory / CVE PublicationProduction Patch AvailableFirst Observed ExploitationKEV AddedDays: Advisory → PatchDays: Patch → KEVCISA Due Date
CVE-2026-86060September 3 / September 5, 2026September 3, 2026Attacks observed from at least September 2, 2026. The true first occurrence may be earlier.September 10, 202607September 13, 2026
CVE-2026-67277September 3 / September 5, 2026September 3, 2026Exact date unavailable. KEV confirms known exploitation.September 10, 202607September 13, 2026

Affected branches and documented production fixes

ScopePublished Affected RangeDocumented Fixed ReleaseRelease Date
Both CVEs: RouterOS 6.x6.0.0 up to, but not including, 6.49.216.49.21 (long-term)September 3, 2026
Both CVEs: earlier RouterOS 7.x range7.0.0 up to, but not including, 7.23.47.23.4 (long-term)September 3, 2026
Both CVEs: RouterOS 7.24 range7.24 up to, but not including, 7.24.27.24.2 (stable)September 3, 2026

Version-data discrepancy: the CVE-2026-67277 record also contains a CPE applicability range from 0.0.0 to below 7.25.1, conflicting with its explicit affected-version list and named fixes. The table above reproduces the explicit branch ranges corroborated by the dated disclosure and vendor guidance. The conflicting CPE field is not silently substituted for them.

Statistical Distribution and Outliers

Both patch-to-KEV observations are seven days, so the range is zero and neither CVE is a timing outlier. The equality of the mean and median describes this shared schedule; it does not establish a typical RouterOS or industry-wide exploitation window.

The exploitation evidence has a different shape: one in-scope case has a minimum pre-production-patch lead, while the other lacks a dated observation. There is no defensible two-CVE average for that metric. The −2-day publication-to-patch values also describe a separate event pair and must not be mistaken for an exploitation duration.

Vulnerability Class Breakdown

CVEAffected FunctionVulnerability ClassCWEPublished Severity
CVE-2026-86060SSH login handlingImproper neutralization of argument delimiters; privilege escalationCWE-88Critical — CVSS v4.0 9.2
CVE-2026-67277Bandwidth-test serviceMissing authentication for a critical function; kernel memory disclosure and denial of serviceCWE-306High — CVSS v4.0 8.8

There is only one example of each weakness class. Their matching release and catalog dates cannot support a conclusion that argument-handling and missing-authentication vulnerabilities generally have the same exploitation timing. The common schedule is the observable finding; a class-level trend is not.

Notable Case Highlights

CVE-2026-86060: keep SSH-chain evidence within its documented scope

The public report pairs CVE-2026-86060 with CVE-2026-67276, an SSH authentication-bypass issue outside the dataset. Its dated observation establishes exploitation before the production releases. It does not establish the true earliest attack or the full duration of the campaign.

Importantly, the two CVEs selected for this post are not the reported two-part SSH chain. The bandwidth-test CVE must not be substituted for the separately identified SSH authentication-bypass vulnerability.

CVE-2026-67277: a separate exposure path with the same patch dates

The bandwidth-test issue illustrates why identical chronology does not imply identical impact. The published technical description identifies premature acceptance of a related connection, leakage of uninitialized packet-buffer data, and a size-validation flaw capable of restarting the kernel. CISA's entry establishes known exploitation, but the reviewed record does not date its first occurrence.

Historical Trend Comparison

The preceding September 9 post in this series emphasized disclosure-to-KEV intervals across a different cohort. This article distinguishes a bounded pre-production-patch exploitation finding from its shared patch-to-KEV interval. Those measures cannot be compared directly to declare that exploitation is accelerating or that the gap is widening.

A meaningful series comparison would retain the same event definitions and distinguish CVE-level counts from shared release events. With only two entries from one product update cycle, this post describes a specific chronology rather than a broader trend.

MITRE ATT&CK Mapping

One limited behavioral mapping is supported. It is an analytical interpretation of reported SSH-chain activity, not a mapping inferred merely from a CWE or applied to both CVEs.

TacticTechniqueEvidence and Scope
PersistenceT1136.001 — Create Account: Local AccountThe SSH-chain report documents unauthorized account creation, including a highly privileged account named ops. This supports a local-account mapping for that reported activity, not for CVE-2026-67277.

No cohort-wide sequence covering initial access, execution, persistence, and command and control is assigned. Additional mappings would require additional attributable behavior.

Risk Context for Organizations

The operational lesson is not that defenders had seven safe days. It is that fixes were available before the formal KEV signal. An organization that waits for catalog inclusion before reviewing an explicit vendor security update can delay its response without evidence that the intervening period is safe.

The catalog preserves a three-day due-date interval for both entries, but its forensic-triage flags differ:

CVECatalog Due DateForensic-Triage FlagKnown Ransomware Campaign Use
CVE-2026-86060September 13, 2026YesUnknown
CVE-2026-67277September 13, 2026NoUnknown

A “No” triage flag is not evidence that a device is uncompromised, and “Unknown” ransomware use is not a confirmed absence of ransomware activity. Both recorded due dates had passed by the September 25 source-review date.

CISA's September 10 alert places federal requirements under BOD 26-04 and identifies Federal Civilian Executive Branch agencies as its scope. Other organizations should apply their own risk and compliance requirements rather than treat a catalog date as a universal legal deadline. Exposure and evidence of compromise remain relevant regardless of that distinction.

Detection and Patch Prioritization Considerations

  1. Confirm the branch as well as the version. Match each device to the affected ranges and documented production fixes above. Resolve inconsistent version data against the explicit advisory and CVE descriptions instead of applying a single unqualified “older than” check across all branches.
  2. Review exposed services separately. Assess SSH reachability for the login-path issue and bandwidth-test reachability for the separate btest vulnerability. MikroTik's advisory recommends keeping SSH away from untrusted networks and restricting management access.
  3. Treat patching and compromise review as separate tasks. After upgrading, inspect unfamiliar users, scripts, and configuration changes. The vendor explicitly recommends this review even when RouterOS is not marked Flagged.
  4. Investigate the Flagged state before clearing it. The RouterOS device-mode documentation says to assume compromise when flagged, audit the configuration, and change system passwords after the audit. Simply removing the warning is not equivalent to establishing a trusted state.
  5. Record actual completion. Preserve the installed version, relevant exposure changes, review findings, and any unresolved exceptions. A release announcement or a successful download is not evidence that every device has been remediated.

Key Takeaways

  • The two CVEs share a seven-day production-patch-to-KEV gap, with a mean and median of seven days.
  • The vendor advisory and production releases precede the CVE publications; these are distinct events and must remain distinct date fields.
  • The SSH case has a minimum one-day pre-production-patch exploitation lead; the bandwidth-test case has no equivalent dated interval.
  • Shared release dates do not establish a shared attack chain or an industry-wide timing pattern.
  • Version validation, service-exposure review, and compromise assessment answer different questions; none should be treated as a substitute for the others.

Conclusion

This cohort combines an identical patch-to-KEV interval with unequal exploitation evidence. A dated attack observation establishes a minimum pre-production-patch lead for the SSH case; the bandwidth-test case remains undated. The shared catalog schedule does not erase that distinction.

For ongoing patch and compliance monitoring, retain attack observations, release dates, CVE publications, and catalog additions separately, then verify the deployed device. A bounded pre-patch finding is more useful than an invented exact duration, just as a release date is not proof that prior compromise has been removed.

Constantly Fix Risks with Saner Patch Management

Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.

The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026

Open CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation
CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

CVE Research

CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

Sep 24, 2026