CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 66%
- Investor
- Investor 7%
Reality
- Evidence64
- Adoption70
- Hype gap+8
- Incentives
- Insufficient
- Confidence62
Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.
Perspective Coverage
4 publishers
- Builder
- Builder 21%
- Operator
- Operator 68%
- Investor
- Investor 11%
Reality
- Evidence80
- Adoption40
- Hype gap+5
- Incentives
- Insufficient
- Confidence75
CERT Polska found that Messenger Pro cleared Google Play review as a 40MB base APK whose malicious loader was 0.552% of its code. Its real payload never shipped to the store; stage two pulled it from an Alibaba Cloud bucket only after install.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence58
CERT Polska tied 17 Google Play apps and 852 Meta ads to one Android toll-fraud operation aimed at Polish users. Its billing code arrived after install from an object-storage bucket. The public ad records told analysts more than the store listing did.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
Qbusoft confirmed an attacker stole patient data from its Medyc clinic software through an SQL injection flaw that went unnoticed for about 17 days. It is the second Polish clinic-software supplier to lose ID numbers in weeks, after MyDr lost data on nearly 19 million people in August.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 54%
- Investor
- Investor 18%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence72
CVE-2026-86060, the privilege half of the MikroTrick chain CERT Polska analysed, lets an SSH client set its own policy mask and take RouterOS full-group admin. The September 2026 releases fix it, and a scan found 9,559 devices reachable over SSH.
Reality
- Evidence62
- Adoption52
- Hype gap−3
- Incentives22
- Confidence58
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.
Perspective Coverage
8 publishers
- Builder
- Builder 19%
- Operator
- Operator 73%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption45
- Hype gap+18
- Incentives30
- Confidence72
MikroTik published RouterOS fixes in four branches with no CVE and no technical detail. The same upgrade runs a compromise check and writes a critical log entry marking the device Flagged.
Publishers:cert.pl · forum.mikrotik.com · helpnetsecurity.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 71%
- Investor
- Investor 7%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap−40
- Incentives45
- Confidence72
Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.
Perspective Coverage
13 publishers
- Builder
- Builder 21%
- Operator
- Operator 76%
- Investor
- Investor 3%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence66
CERT Polska rebuilt the MikroTrick attack chain from MikroTik's unlabeled September 3 patch and had a working exploit for CVE-2026-86060 in about an hour. The fix quietly disables a rogue "ops" account, evidence the chain was already exploited in the wild.
Reality
- Evidence68
- Adoption62
- Hype gap+8
- Incentives45
- Confidence60
CERT Polska's breakdown of the September RouterOS compromises names two bugs, CVE-2026-67279 and CVE-2026-86060, and the forum logs that match the chain start on September 2, a day before MikroTik shipped fixes.
Reality
- Evidence74
- Adoption52
- Hype gap−8
- Incentives35
- Confidence70
CERT Polska confirmed exploitation of the MikroTrick chain on September 5, and the two bugs need no password and no private key, only a reachable SSH service, so the firewall rule scopes the risk before any build audit can.
Reality
- Evidence55
- Adoption70
- Hype gap−8
- Incentives40
- Confidence58
Two RouterOS flaws published to NVD on 2026-09-05 both sit in code that runs before a session has proven who it is. An upgrade closes them. Which management services answer from the internet is still an open question.
Reality
- Evidence64
- Adoption72
- Hype gap−16
- Incentives34
- Confidence66
Politico reported that ENISA and CERT-EU ran an advanced OpenAI model over an EU project's code and got four fixed flaws out of it. Poland's CERT, doing the same kind of work, said it tested every hypothesis on real systems.
Reality
- Evidence58
- Adoption62
- Hype gap+16
- Incentives71
- Confidence52
CERT Polska reports active exploitation on internet-facing MikroTik routers, where the chain needs no private key and no user interaction, and the fixed builds close the bypass without explaining how attackers learned the account details.
Reality
- Evidence60
- Adoption42
- Hype gap+8
- Incentives28
- Confidence54
CERT Polska says CVE-2026-73570 is already being exploited. Two of the three preconditions are configuration, not code, which makes reachability the control you can change now.
Reality
- Evidence58
- Adoption42
- Hype gap−8
- Incentives30
- Confidence55