MikroTik RouterOS · Forgejo · IBM ContextForge MCP Gateway
Date: 2026-09-11 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added two MikroTik RouterOS vulnerabilities to the KEV Catalog following evidence of active exploitation; both affect the btest service or trusted policy handling and have a 2026-09-13 remediation deadline. Newly published enterprise-relevant vulnerabilities include unauthenticated remote code execution in Forgejo, default administrative credentials in IBM ContextForge MCP Gateway, and authentication-bypass risks in a SAML library. Review internet-facing developer, AI and management platforms urgently.
Critical Vulnerabilities
CVE-2026-67277 — MikroTik RouterOS
- Severity: Not supplied; CISA KEV-listed
- EPSS: Not supplied
- Technical detail: A missing-authentication vulnerability in the RouterOS
btestservice can allow kernel memory disclosure and denial of service. Exposure depends on whether the affected service is enabled and reachable; affected routers may include perimeter, branch and service-provider infrastructure. - Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-10. CISA remediation is due by 2026-09-13.
- Remediation: Upgrade RouterOS to the vendor-fixed version, disable or restrict
btestwhere not required, limit management access to trusted networks, and review router logs for unexpected service access, configuration changes and administrative activity.
CVE-2026-86060 — MikroTik RouterOS
- Severity: Not supplied; CISA KEV-listed
- EPSS: Not supplied
- Technical detail: Improper neutralization of argument delimiters in a RouterOS command can allow an attacker to alter the trusted RouterOS policy mask and escalate privileges. The issue is particularly relevant to routers exposed to untrusted management or service traffic.
- Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-10. CISA remediation is due by 2026-09-13.
- Remediation: Apply the RouterOS security update immediately. Restrict administrative interfaces, validate trusted-policy settings, audit privileged commands and investigate unexpected policy or account changes.
CVE-2026-89094 — Forgejo
- Severity: CVSS 9.9
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: Forgejo versions before 15.0.8 and 16.0.4 may permit remote code execution through a crafted template repository. Improper handling of files under
.forgejo/templatecan cause attacker-controlled template expansion, making internet-facing code-hosting and self-hosted development platforms high-value targets. - Exploitation status: NEW — no exploitation reported in the supplied data.
- Remediation: Upgrade to Forgejo 15.0.8, 16.0.4 or later, according to the deployed branch. Review repositories and template content for unauthorized changes, rotate credentials available to Forgejo runners, and restrict administrative and repository-management interfaces.
CVE-2026-78573 — IBM ContextForge MCP Gateway
- Severity: CVSS 9.8
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: ContextForge MCP Gateway 1.0.0–1.0.7 uses default credentials that may allow a remote attacker to obtain administrative access. Internet-exposed AI gateways are especially sensitive because administrative control may expose connected model providers, tools, prompts, data sources and service credentials.
- Exploitation status: NEW — no exploitation reported in the supplied data.
- Remediation: Upgrade to the vendor-fixed release, immediately replace all default credentials and rotate connected API keys or tokens. Remove direct internet exposure, enforce strong administrative authentication and review gateway access, configuration and tool-invocation logs.
CVE-2026-89042 — passport-saml-encrypted
- Severity: CVSS 9.3
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: Versions through 0.1.13 may accept unsigned SAML responses when the certificate option is not supplied, allowing authentication bypass. Applications using this library in identity-provider or service-provider integrations may be vulnerable depending on configuration and whether signature validation is enforced elsewhere.
- Exploitation status: NEW — no exploitation reported in the supplied data.
- Remediation: Upgrade or replace the affected library, require SAML signature validation independently of optional certificate configuration, and review authentication logs for anomalous assertions, new sessions and unexpected privilege changes.
ONGOING
CVE-2026-75650(Adobe Commerce/Magento): actively exploited in StyleSmuggler; patch immediately and hunt for web shells and payment-file modification.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-81963/CVE-2026-85880(Windows): actively exploited; complete September update deployment.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC remain reported; verify patching and hunt for web shells.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation remains reported; remediate before the 2026-09-14 deadline.CVE-2026-79724,CVE-2026-81204and related Langflow flaws: newly published issues affect the already reported Langflow platform; restrict exposure and upgrade to a vendor-fixed release.
European Advisories
CERT-EU advisory 2026-012 (Check Point VPN): ongoing emergency remediation remains required for the two CVSS 9.8 unauthenticated RCE vulnerabilities affecting Security Gateway, Security Management Server and Spark Firewall VPN deployments.
WID-SEC-2026-3286 (Budibase): covered in the previous briefing; apply vendor fixes and review externally accessible deployments.
BSI/CERT-Bund issued updates for Kemp LoadMaster, Samba, Linux Kernel, BIND, Firefox/Thunderbird, Red Hat Enterprise Linux, NGINX, FreeRDP, Node.js, Apache HTTP Server, QEMU and Netty. These are status updates to previously tracked advisories; prioritize internet-facing, identity, VPN and administrative systems.
Active Threats and Campaigns
- MikroTik RouterOS exploitation — NEW: CISA confirmed active exploitation of
CVE-2026-67277andCVE-2026-86060. Identify exposed RouterOS services, patch before the 2026-09-13 deadline and investigate policy changes, privileged commands and unusual router activity. - PaperCut exploitation — ONGOING: The AI-assisted campaign targeting PaperCut NG/MF remains active, with at least 395 organizations reportedly compromised. Continue web-shell, account and outbound-connection hunting.
- Cisco FMC exploitation — ONGOING: Ransomware- and state-linked clusters continue to be associated with exploitation. Treat unpatched or internet-reachable management systems as potentially compromised.
- BlueMoon exploit kit — ONGOING: Reporting continues to describe Windows and Chrome zero-day exploitation; supplied data contains no CVE identifiers or IOCs.
Security News and Context
- Windows Server September updates reportedly disrupt Remote Desktop Services on Windows Server 2019, 2022 and 2025. Validate RDS functionality during rollout and maintain recovery options.
- Surfshark disclosed unauthorized access to an internal test server and proxy infrastructure following an internet-exposed configuration error.
- Mantax Otax Android malware combines file encryption, data theft and harassment; reinforce mobile application controls.
Recommended Actions
- Patch RouterOS for
CVE-2026-67277andCVE-2026-86060before 2026-09-13; restrictbtestand management access. - Identify and patch Forgejo instances; inspect template repositories and runner credentials.
- Remove default credentials from IBM ContextForge MCP Gateway and rotate connected secrets.
- Remediate
passport-saml-encryptedand verify mandatory SAML signature validation. - Test RDS availability after September Windows updates and prepare rollback or alternate access procedures.
- Continue PaperCut, Cisco FMC, SharePoint, Magento, N-central, Windows and Check Point investigations and patching.
- Continue remediation of previously reported items: MikroTik RouterOS, Check Point VPN, Langflow, PaperCut, Cisco FMC, SharePoint, Magento and N-central.