MikroTik RouterOS Vulnerabilities Under Active Exploitation

MikroTik RouterOS Vulnerabilities Under Active Exploitation

First seen 6 Sep 2026, 09:03 UTC Cert.Plmikrotik.comThehackernewscert.pl 78.7

Article Content

Browse articles
ThreatCluster

CERT Polska has identified six critical vulnerabilities in MikroTik RouterOS, with two of them allowing full control of devices via SSH without authentication. The vulnerabilities, collectively known as MikroTrick, are being actively exploited in the wild, particularly against devices accessible from the internet. Affected systems include various versions of RouterOS, with specific CVEs published on September 5, 2026: CVE-2026-67276, CVE-2026-86060, and CVE-2026-67277. MikroTik has released patches in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and users are urged to update immediately. The vulnerabilities impact the SSH server and client, bandwidth-test service, and WebFig interface. Users should check for unauthorized configurations post-update. The situation is critical, with ongoing attacks confirmed.

Key Points: • Six critical vulnerabilities in MikroTik RouterOS are actively exploited. • Two vulnerabilities allow full device control via SSH without authentication. • Immediate updates are required to mitigate the risk of exploitation.

Ask AI about this cluster

Timeline

2026-09-05
CVE-2026-67276 published
SSH authentication bypass vulnerability allows attackers to log in without the private key.
Cert.Pl
2026-09-05
CVE-2026-86060 published
Privilege escalation via crafted username in SSH login mechanism confirmed.
Cert.Pl
2026-09-05
CVE-2026-67277 published
Memory disclosure and crash vulnerability via bandwidth-test service identified.
Cert.Pl
2026-09-06
Patches released
MikroTik released updates in multiple versions to address the vulnerabilities.
mikrotik.com
Recent
Active exploitation observed
CERT Polska confirmed ongoing attacks against RouterOS devices with SSH accessible from the internet.
Cert.Pl