Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ssh (3 articles)Clear

Chained MikroTik RouterOS SSH flaws let attackers seize exposed routers without authentication

CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.

Check
Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, remove SSH from public interfaces, and check exposed routers for signs of takeover.
Affected
Internet-exposed MikroTik routers on unpatched RouterOS let an unauthenticated attacker chain the two SSH flaws into full administrative control.
Fix
Patch RouterOS to the fixed releases, restrict SSH to management networks or disable it, and rotate credentials on any reachable device.

Public exploit released for critical libssh2 flaw affecting curl, Git, and more

A public proof-of-concept has been released for a critical flaw in libssh2 (CVE-2026-55200), the client-side SSH library embedded in curl, Git, PHP, backup agents, firmware updaters, and countless appliances. A malicious or compromised SSH server can send a crafted packet that corrupts memory on the connecting client, with no credentials or user interaction needed, potentially leading to code execution. Rated 9.2, the bug affects all versions through 1.11.1. The fix was merged into the source on June 12, but no tagged release exists yet, so distributions are backporting it. The hardest part is that libssh2 is often statically bundled, so package updates miss those copies entirely.

Check
Inventory everything that links libssh2, including statically bundled copies inside curl, Git, PHP, backup tools, and appliances that package managers will not flag, especially anything connecting to untrusted SSH servers.
Affected
Any software using libssh2 through version 1.11.1 that connects to an untrusted or attacker-controlled SSH server (CVE-2026-55200); the malicious server, not the client, triggers the memory corruption without authentication.
Fix
Apply a build that includes the upstream fix, whether a distribution backport or patched source, watch vendor advisories for tagged releases, and restrict outbound SSH to untrusted servers until patched.

New Linux backdoor 'PamDOORa' silently steals SSH credentials from every user logging into a compromised server - and erases its tracks from the logs

Group-IB and Flare disclosed PamDOORa, a new Linux backdoor for sale on the Russian-speaking Rehub cybercrime forum at $900 (down from $1,600). PamDOORa hijacks the Linux Pluggable Authentication Module (PAM) framework that handles SSH logins - so it intercepts every legitimate user's password as they authenticate, before any application-level logging fires. The backdoor injects a malicious pam_linux.so module into the authentication stack rather than replacing files. It also tampers with lastlog, btmp, utmp, and wtmp to erase attacker login traces - meaning incident response teams who SSH in to investigate will have their own credentials silently stolen. Group-IB notes the abuse method is not yet in MITRE ATT&CK.

Check
Audit /etc/pam.d/ for unfamiliar pam_*.so modules, particularly pam_linux.so. Compare loaded PAM modules against your distribution's default set. Hunt /tmp for files with random names containing XOR-encrypted credential captures.
Affected
All x86_64 Linux servers running OpenSSH for remote access. PamDOORa is post-exploitation, so attackers must already have root - but once installed it captures every SSH credential and persists invisibly. Acute risk: any Linux server compromised at any point in the past, regardless of remediation - PamDOORa survives standard cleanup unless PAM-specific auditing was performed.
Fix
Enable SELinux or AppArmor in enforcing mode to constrain PAM module loading. Install Auditd with DISA-STIG rules to alert on /etc/pam.d/ changes. Deploy rkhunter or chkrootkit for routine PAM rootkit detection. Treat any compromised Linux server as having fully exposed credentials - rotate every SSH key, password, and token.