CVE Tools

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Help Net SecurityBy Sinisa Markovic

Reported exploitedMikroTik RouterOS

Our summary

CERT Polska reported active exploitation of a vulnerability chain in MikroTik RouterOS that allows attackers to seize full control of devices with internet-exposed SSH services without prior authentication. The attack leverages CVE-2026-67276, an SSH authentication bypass, combined with CVE-2026-86060, a privilege escalation flaw, to establish administrative access. Additionally, CVE-2026-67277 was identified alongside three other lower-severity issues affecting certificate handling and web interfaces.

Vendors have released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Administrators are urged to apply these updates immediately, disable exposed services like SSH as a temporary mitigation, and audit device configurations for unauthorized users such as 'ops' or suspicious script entries.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store