Attackers exploit MikroTik RouterOS flaws CVE-2026-67276 and CVE-2026-86060 to hijack internet-exposed routers

Attackers are actively taking over some MikroTik routers that expose Secure Shell (SSH) to the internet. Poland’s CERT says the attacks chain CVE-2026-67276, an SSH authentication bypass in RouterOS, with CVE-2026-86060, an SSH privilege-escalation flaw, to gain full administrative control; CERT also highlighted CVE-2026-67277, which can leak kernel memory or crash routers via the bandwidth-test service. MikroTik fixed the issues in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.
Why it matters: Organizations and individuals using MikroTik routers could have their network edge device silently taken over, giving attackers a foothold into traffic and internal systems. This is urgent for anyone with internet-exposed RouterOS management or SSH services: patch now, restrict external access, and if compromise is suspected, reset and rebuild the router and rotate credentials.

Sources

MikroTik Patches Critical Flaws Chained to Hack Routers
Ionut Arghire 2026.09.08 98% relevant
This source confirms MikroTik has released patches for the actively exploited 'MikroTrick' chain, adds the fixed RouterOS versions (7.25beta3, 7.24.2, 7.23.4, 6.49.21), lists four additional CVEs fixed in the same update, and provides defensive indicators including the 'ops' account artifact, source IPs, and advice to check for 'Flagged' log entries.
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Bill Toulas 2026.09.07 100% relevant
This article establishes a new tracked story by tying active in-the-wild exploitation to a specific MikroTik RouterOS exploit chain, named CVEs, fixed versions, and operational indicators of compromise.
← Back to all stories