Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers chained SSH authentication bypass CVE-2026-67276 and privilege flaw CVE-2026-86060 to fully hijack internet-exposed MikroTik routers before patches existed.
CERT Polska disclosed six MikroTik RouterOS vulnerabilities on September 5, 2026, and confirmed real-world exploitation of SSH-exposed devices beginning around September 2, before public disclosure and patched releases. The actively exploited MikroTrick chain pairs CVE-2026-67276, an SSH authentication bypass, with CVE-2026-86060, a session privilege manipulation flaw, both CVSS 9.2, yielding full administrative control of internet-facing routers. Bishop Fox independently reproduced a related chain using CVE-2026-67279 and CVE-2026-86060 and found post-compromise persistence, including unauthorized full-privilege accounts, scripts, and schedulers showing the unusual owner="0" value. Fixes are available in RouterOS 6.49.21, 7.23.4, and 7.24.2, but updating cannot remove attacker-created persistence.