Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

MikroTik Patches Critical Flaws Chained to Hack Routers

0
Critical
Vulnerability
Published: 09/08/2026 (09/08/2026, 11:15:00 UTC)
Source: SecurityWeek

Description

MikroTik has released patches for six vulnerabilities in RouterOS, including a critical set of flaws dubbed MikroTrick that allow attackers to bypass SSH authentication, manipulate privileges, and take full control of affected routers. Two of these vulnerabilities have been confirmed exploited in the wild, with attackers chaining them to compromise devices accessible via SSH from public networks. The vendor and CERT Poland urge immediate patching and recommend blocking SSH access from untrusted sources. The vulnerabilities include authentication bypass, privilege escalation, memory disclosure, denial-of-service, TLS impersonation, file tampering, and disclosure of root-owned files. Attackers have been observed creating unauthorized accounts and exploiting these flaws since early September 2026. MikroTik provides fixed versions to mitigate these issues.

Affected software

Affected versions
>=7.0.0 <7.24.2>=7.0.0 <7.23.4>=6.0.0 <6.49.21

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 11:22:22 UTC

Technical Analysis

The MikroTrick vulnerabilities in MikroTik RouterOS consist of multiple critical security flaws that can be chained to bypass SSH authentication, escalate privileges within SSH sessions, and ultimately take full control of affected routers. CERT Poland confirmed active exploitation involving the creation of unauthorized accounts named 'ops' originating from specific IP addresses. The affected vulnerabilities include CVE-2026-67276 (SSH authentication bypass, CVSS 9.2), CVE-2026-86060 (SSH session privilege manipulation, CVSS 9.2), and CVE-2026-67277 (memory disclosure and denial-of-service, CVSS 8.8), among others. Additional flaws allow TLS server impersonation, unauthenticated file tampering, and disclosure of root-owned configuration files. MikroTik has issued patches in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 to address these vulnerabilities. The vendor recommends immediate updates and restricting SSH access to trusted sources to prevent exploitation.

Potential Impact

Successful exploitation of these chained vulnerabilities enables attackers to bypass authentication mechanisms, gain unauthorized administrative access, overwrite router configuration files, and fully compromise MikroTik devices. This can lead to complete device takeover, unauthorized network control, and potential disruption or interception of network traffic. The presence of unauthorized accounts and exploitation attempts indicates active targeting of devices with exposed SSH services. The vulnerabilities pose a critical risk to affected MikroTik routers accessible from public networks.

Mitigation Recommendations

MikroTik has released official patches addressing these vulnerabilities in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Users should apply these updates immediately to prevent exploitation. Additionally, MikroTik recommends blocking SSH access from untrusted sources to reduce exposure. Monitoring router logs for entries flagged as 'Flagged' may help detect compromised devices. The vendor and CERT Poland advisories emphasize that updating to the latest patched versions prevents these attacks. No further mitigation steps are indicated beyond patching and restricting SSH access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/","fetched":true,"fetchedAt":"2026-09-08T11:22:14.252Z","wordCount":1048}

Threat ID: 6a9fefe6acd9273b498ea253

Added to database: 09/08/2026, 11:22:14 UTC

Last enriched: 09/08/2026, 11:22:22 UTC

Last updated: 09/08/2026, 16:58:29 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses