// MikroTik
Active Exploitation Surge: MikroTik, PaperCut, and Android Threats Demand Immediate Action
By NeoShield AI Threat Desk · Published 2026-09-11 · 4 min read
#MikroTik#RouterOS#CVE-2026-67277#CVE-2026-86060#PaperCut#Android#Mantax Otax#CISA KEV
From CISA-catalogued MikroTik router flaws to AI-orchestrated PaperCut attacks and a dual-threat Android malware strain, September 11 brings a wave of high-severity threats that security teams must address today.
The most urgent items today come directly from CISA's Known Exploited Vulnerabilities catalog. Two MikroTik RouterOS vulnerabilities, CVE-2026-67277 and CVE-2026-86060, have been added based on confirmed active exploitation in the wild. CVE-2026-67277 is a missing authentication vulnerability for a critical function, meaning an unauthenticated remote attacker can interact with privileged router capabilities without presenting any credentials. CVE-2026-86060 involves improper neutralization of argument delimiters in a command, a class of flaw that can allow attackers to inject unintended commands into router operations. MikroTik devices are extraordinarily common in enterprise edge environments, ISP infrastructure, and small-to-medium business networks worldwide, which makes these vulnerabilities high-value targets for threat actors seeking persistent network footholds. Organizations running RouterOS should treat patching as a same-day priority and immediately audit whether management interfaces are exposed to the internet.
Running in parallel, a sophisticated AI-powered campaign has been actively exploiting vulnerable PaperCut NG and MF print management servers, reportedly compromising approximately 395 organizations. The threat actor, assessed as likely Russian-speaking, deployed hundreds of AI agents to automate the development and execution of the exploitation chain at a scale that would have been impractical with purely manual methods. This is a significant operational milestone: AI is no longer a theoretical force multiplier for attackers — it is being used in active campaigns right now. PaperCut vulnerabilities have been in the public eye for some time, and any organization still running unpatched PaperCut instances should consider them actively targeted. Beyond patching, security teams should review PaperCut server logs for anomalous API calls, unexpected administrative account creation, and unusual print job routing behavior.
On the mobile front, a new Android malware strain dubbed Mantax Otax has emerged with a particularly aggressive dual-purpose design. It combines ransomware-style file encryption with spyware capabilities, stealing sensitive data while simultaneously harassing victims through spam and intimidation tactics. This combination is designed to maximize pressure on victims and reduce the likelihood of calm, methodical incident response. Enterprise mobile device management programs should treat this as a prompt to review sideloading policies, application allowlisting, and the scope of permissions granted to installed applications. Employees should be reminded that applications requesting broad storage, contact, or messaging permissions warrant scrutiny regardless of their apparent legitimacy.
The Surfshark VPN breach disclosure adds another dimension to today's briefing. A configuration error exposed an internal test server to the internet, and attackers accessed it. This is a textbook example of shadow infrastructure risk — systems that exist outside normal change management and security review cycles. Test, staging, and development environments frequently carry production-equivalent credentials, internal network access, or sensitive data, yet they are often excluded from vulnerability scanning schedules and hardening baselines. Every organization should maintain an inventory of internet-facing assets that includes non-production systems and subject them to the same exposure review as production infrastructure.
Finally, the broader Android vulnerability landscape reported this week — encompassing over 200 flaws alongside browser-based phishing chains and large-scale scam shop networks — reinforces that the attack surface for end users remains enormous. Browser extensions requesting excessive permissions, trusted services being weaponized as phishing relay points, and persistent old vulnerabilities all reflect an environment where defenders must assume that user endpoints are under constant pressure.
Defensive priorities for today:
- Patch MikroTik RouterOS immediately for CVE-2026-67277 and CVE-2026-86060; remove management interfaces from internet exposure and enforce firewall rules restricting administrative access to trusted IP ranges only
- Audit and patch all PaperCut NG and MF instances; review server logs for signs of compromise including new admin accounts, configuration changes, and anomalous API activity
- Enforce mobile device management policies that restrict sideloading, limit application permissions, and flag applications requesting access to storage, contacts, or messaging without clear business justification
- Conduct an immediate inventory of all internet-facing systems including test, staging, and development environments; apply network segmentation and authentication controls to any non-production system with external exposure
- Review browser extension policies across the enterprise and remove or restrict extensions with excessive permission scopes
- Brief SOC teams on AI-accelerated attack timelines — the window between vulnerability disclosure and mass exploitation is shrinking, and detection and response playbooks must reflect that urgency
This briefing is informational and intended to support situational awareness; always consult official vendor advisories and CISA guidance for authoritative remediation instructions specific to your environment.
Related articles
Patch Storm: Six Critical Exploited Flaws Demand Immediate Action Across Enterprise Stacks
A wave of actively exploited critical vulnerabilities is hitting enterprise infrastructure simultaneously, spanning Cisco…
Patch TuesdayPatch Tuesday Avalanche, CRA Deadline, and Active Zero-Days: September 9 Threat Briefing
Microsoft's record-shattering September 2026 Patch Tuesday drops alongside two actively exploited zero-days and fresh CISA KEV…
MagentoStyleSmuggler to JSCeal: Six Critical Threats Demanding Immediate Action Today
From a Magento zero-day deploying Linux backdoors to session-cookie theft bypassing Google MFA, today's threat landscape is…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.