CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.
An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.
CISA has added a Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is being used in real attacks, requiring federal agencies to patch it under a binding deadline. Cisco IOS and IOS XE run the routers and switches behind many enterprise and service-provider networks, so a flaw here can give attackers a foothold deep in the network path. The listing lands amid heightened warnings, including a joint US-and-allies advisory this week urging better router hygiene against Russian state-sponsored targeting of network devices. Network gear is attractive because it often sits unmonitored, stays online for years, and rarely runs endpoint security; timely patching is the main defense.
CERT/CC has warned that several Tenda router firmware versions contain an undocumented authentication backdoor that grants full administrative access to the web management interface. Tracked as CVE-2026-11405, the flaw lives in the login function of the router's web server: if normal password checking fails, the firmware compares the supplied password against a hidden value stored in the device configuration and, on a match, grants admin access regardless of the username. It affects models including the FH1201, W15E, AC10, AC5, and AC6, is baked into the firmware, and cannot be disabled from the interface. Tenda has not responded, so there is no fix, and public exploit tooling is already scanning for vulnerable devices.
Researchers at XLab have documented a previously unknown botnet called AryStinger that has taken over more than 4,000 outdated routers, mostly D-Link DIR-850L and DIR-818LW models, and turned them into proxies for malicious traffic. It spreads by exploiting old, unpatched vulnerabilities and can scan networks, tunnel and proxy traffic, run commands, and tamper with DNS settings to hijack users' browsing. A more advanced Go-based variant targets NAS devices and adds internal network reconnaissance using open-source pentest tools. Infections cluster in South Korea and China but reach Sweden and Southeast Asia too. The compromised devices are end-of-life and will not receive fixes.