mikrotik.com
MikroTik RouterOS Vulnerabilities Under Active Exploitation
Article Content
CERT Polska has identified six critical vulnerabilities in MikroTik RouterOS, with two of them allowing full control of devices via SSH without authentication. The vulnerabilities, collectively known as MikroTrick, are being actively exploited in the wild, particularly against devices accessible from the internet. Affected systems include various versions of RouterOS, with specific CVEs published on September 5, 2026: CVE-2026-67276, CVE-2026-86060, and CVE-2026-67277. MikroTik has released patches in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and users are urged to update immediately. The vulnerabilities impact the SSH server and client, bandwidth-test service, and WebFig interface. Users should check for unauthorized configurations post-update. The situation is critical, with ongoing attacks confirmed.
Key Points: • Six critical vulnerabilities in MikroTik RouterOS are actively exploited. • Two vulnerabilities allow full device control via SSH without authentication. • Immediate updates are required to mitigate the risk of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.