CISA added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalog on September 10. The catalog is intended to help organizations prioritize flaws that are known to be exploited, making the listing a signal to review affected systems and remediation status.
For network teams, speed matters: edge devices often sit between internal systems and the public internet, while asset inventories can be incomplete. The advisory does not replace vendor guidance; administrators should verify their specific versions, apply appropriate updates or mitigations and check for evidence of compromise.
A practical response
Start by identifying RouterOS devices and their software versions, including systems managed by service providers. Compare the findings with CISA and vendor instructions, then prioritize exposed or business-critical devices. Patching should be followed by logging and monitoring review where compromise is plausible.
Why KEV listings matter
The KEV catalog helps defenders sort through a large vulnerability backlog by highlighting exploitation evidence. Inclusion is not proof that a particular organization has been attacked, but it is a reason to treat remediation as time-sensitive.

