Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers exploit new MikroTik RouterOS flaws to hijack routers

0
Critical
Vulnerability
Published: 09/07/2026 (09/07/2026, 10:32:40 UTC)
Source: Bleeping Computer

Description

Two critical vulnerabilities in MikroTik RouterOS, CVE-2026-67276 and CVE-2026-86060, are being actively exploited to hijack routers with SSH services exposed to the internet. The first flaw allows SSH authentication bypass via crafted RSA keys, while the second enables privilege escalation through specially crafted usernames. A third vulnerability, CVE-2026-67277, affects the bandwidth-test service allowing memory leaks or remote crashes. MikroTik released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. The vendor added compromise-detection mechanisms in these updates. The Polish CERT agency recommends isolating suspected compromised devices and applying patches promptly. Mitigations include restricting or disabling external SSH and related services until patched. Over 122,000 devices have exposed SSH interfaces, making this a significant threat.

Affected software

Affected versions
>=7.23.0 <7.23.4>=7.24.0 <7.24.2>=6.0.0 <6.49.21

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 10:37:38 UTC

Technical Analysis

MikroTik RouterOS suffers from a chain of two critical SSH-related vulnerabilities: CVE-2026-67276, an SSH authentication bypass caused by incomplete RSA public key validation, and CVE-2026-86060, an SSH privilege escalation via specially crafted usernames. Exploitation allows attackers to log in without the legitimate private key and gain full administrative privileges. A third flaw, CVE-2026-67277, impacts the bandwidth-test service, enabling unauthenticated kernel memory leaks or remote device crashes. These vulnerabilities are actively exploited in the wild, as confirmed by Poland's CERT, which discovered them with AI assistance. MikroTik patched these issues in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and introduced compromise detection features. Indicators of compromise include specific SSH log entries and presence of unauthorized privileged accounts. The advisory stresses that absence of compromise markers does not guarantee device integrity. Mitigation includes applying patches, isolating compromised devices, and restricting external SSH and related services until updates are applied.

Potential Impact

Successful exploitation of CVE-2026-67276 allows attackers to bypass SSH authentication without the legitimate private key, gaining unauthorized access. CVE-2026-86060 enables privilege escalation to full administrative rights on the router. Together, these allow attackers to take full control of MikroTik routers with exposed SSH services. CVE-2026-67277 can cause memory leaks or remote crashes, potentially disrupting router availability. Active exploitation has been observed, with attackers confirmed to have compromised devices. This can lead to unauthorized configuration changes, persistent control, and potential network compromise.

Mitigation Recommendations

MikroTik has released official patches in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 that fix these vulnerabilities and add compromise detection mechanisms. Users should apply these updates immediately. The vendor notes not all configurations are affected, but details were withheld to allow time for patching. If compromise is suspected, isolate the device, preserve logs and configurations, perform a factory reset, and rebuild from trusted configurations while rotating all credentials. Until patches can be applied, restrict or disable externally accessible SSH, WWW/WWW-SSL, and bandwidth-test services. Avoid using built-in SSH clients and outbound TLS connections over untrusted networks. The absence of compromise indicators does not guarantee device integrity, so proactive patching and mitigation are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.78,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a9e93e3acd9273b49748b80

Added to database: 09/07/2026, 10:37:23 UTC

Last enriched: 09/07/2026, 10:37:38 UTC

Last updated: 09/07/2026, 11:27:41 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses