Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: routeros (2 articles)Clear

Chained MikroTik RouterOS SSH flaws let attackers seize exposed routers without authentication

CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.

Check
Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, remove SSH from public interfaces, and check exposed routers for signs of takeover.
Affected
Internet-exposed MikroTik routers on unpatched RouterOS let an unauthenticated attacker chain the two SSH flaws into full administrative control.
Fix
Patch RouterOS to the fixed releases, restrict SSH to management networks or disable it, and rotate credentials on any reachable device.

Exploited MikroTik flaw chain gives full router control over exposed SSH

Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.

Check
Update RouterOS to a fixed release now, take SSH off the internet by restricting it to a management network or VPN, and hunt exposed devices for a rogue user named dash-two.
Affected
Internet-exposed MikroTik RouterOS devices with SSH enabled (CVE-2026-67276); an unauthenticated attacker can bypass SSH authentication and escalate to full administrator, and about 300,000 devices are still exposed and being targeted.
Fix
Patch RouterOS, keep SSH and management interfaces off the public internet, rotate all router and downstream credentials and SSH keys, disable unused services, and rebuild any device confirmed compromised.