← All articles

Chained MikroTik RouterOS SSH flaws let attackers seize exposed routers without authentication

CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.

Check
Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, remove SSH from public interfaces, and check exposed routers for signs of takeover.
Affected
Internet-exposed MikroTik routers on unpatched RouterOS let an unauthenticated attacker chain the two SSH flaws into full administrative control.
Fix
Patch RouterOS to the fixed releases, restrict SSH to management networks or disable it, and rotate credentials on any reachable device.