Hackers exploit new MikroTik RouterOS flaws to hijack routers
Reported exploitedMikroTik RouterOSOur summary
Attackers are actively leveraging a combination of two recently disclosed vulnerabilities in MikroTik RouterOS to gain full administrative control over devices with SSH services exposed to the internet. The exploit chain involves CVE-2026-67276, an authentication bypass flaw stemming from incomplete RSA public key validation, and CVE-2026-86060, a privilege escalation bug triggered by specially crafted usernames. This threat was identified by Poland's CERT agency, which confirmed active in-the-wild exploitation under the name "MikroTrick." A related issue, CVE-2026-67277, also affects the bandwidth-test service, potentially allowing remote denial-of-service conditions.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.