CVE Tools

Hackers exploit new MikroTik RouterOS flaws to hijack routers

BleepingComputerBy Bill Toulas

Reported exploitedMikroTik RouterOS

Our summary

Attackers are actively leveraging a combination of two recently disclosed vulnerabilities in MikroTik RouterOS to gain full administrative control over devices with SSH services exposed to the internet. The exploit chain involves CVE-2026-67276, an authentication bypass flaw stemming from incomplete RSA public key validation, and CVE-2026-86060, a privilege escalation bug triggered by specially crafted usernames. This threat was identified by Poland's CERT agency, which confirmed active in-the-wild exploitation under the name "MikroTrick." A related issue, CVE-2026-67277, also affects the bandwidth-test service, potentially allowing remote denial-of-service conditions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store