Attackers are actively taking over some MikroTik routers that expose Secure Shell (SSH) to the internet. Poland’s CERT says the attacks chain CVE-2026-67276, an SSH authentication bypass in RouterOS, with CVE-2026-86060, an SSH privilege-escalation flaw, to gain full administrative control; CERT also highlighted CVE-2026-67277, which can leak kernel memory or crash routers via the bandwidth-test service. MikroTik fixed the issues in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.
Why it matters: Organizations and individuals using MikroTik routers could have their network edge device silently taken over, giving attackers a foothold into traffic and internal systems. This is urgent for anyone with internet-exposed RouterOS management or SSH services: patch now, restrict external access, and if compromise is suspected, reset and rebuild the router and rotate credentials.
Ionut Arghire
2026.09.08
98% relevant
This source confirms MikroTik has released patches for the actively exploited 'MikroTrick' chain, adds the fixed RouterOS versions (7.25beta3, 7.24.2, 7.23.4, 6.49.21), lists four additional CVEs fixed in the same update, and provides defensive indicators including the 'ops' account artifact, source IPs, and advice to check for 'Flagged' log entries.
Bill Toulas
2026.09.07
100% relevant
This article establishes a new tracked story by tying active in-the-wild exploitation to a specific MikroTik RouterOS exploit chain, named CVEs, fixed versions, and operational indicators of compromise.
← Back to all stories