Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Reported exploitedMikroTik RouterOSOur summary
CERT Polska reported active exploitation of a vulnerability chain in MikroTik RouterOS that allows attackers to seize full control of devices with internet-exposed SSH services without prior authentication. The attack leverages CVE-2026-67276, an SSH authentication bypass, combined with CVE-2026-86060, a privilege escalation flaw, to establish administrative access. Additionally, CVE-2026-67277 was identified alongside three other lower-severity issues affecting certificate handling and web interfaces.
Vendors have released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Administrators are urged to apply these updates immediately, disable exposed services like SSH as a temporary mitigation, and audit device configurations for unauthorized users such as 'ops' or suspicious script entries.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.