ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

MikroTik RouterOS flaws actively exploited for full router takeover; CISA adds two to KEV catalog with September 13 deadline

highExploit / PoCexploited in the wildimportance 82CVE-2026-67276CVE-2026-86060CVE-2026-67277
What's new: This is the first merged summary for this story. It consolidates three reports spanning September 9–11, 2026, tracing the story's escalation from MikroTik's initial patch release and CERT Polska's active-exploitation confirmation (CSO Online, Sept 9), through Canada's Cyber Centre alert AL26-020 and CISA's KEV additions (Sept 10), to the September 13 federal remediation deadline and BOD 26-04…
Merged summary · glm-5.3 · rewritten as coverage arrives

MikroTik patched six RouterOS vulnerabilities found by CERT Polska, with the 'MikroTrick' chain (CVE-2026-67276 + CVE-2026-86060) enabling unauthenticated full takeover of SSH-exposed routers; on September 10, 2026, CISA added CVE-2026-67277 and…

MikroTik released patches for six RouterOS vulnerabilities discovered by CERT Polska, affecting the SSH server/client, the bandwidth-test service, X.509 handling, and WebFig. Fixed versions are RouterOS 7.25 beta 3, 7.24.2 (Stable), 7.23.4 (Long-Term), and 6.49.21. Three of the flaws are individually tracked: CVE-2026-67276, an RSA public-key validation / improper cryptographic signature verification flaw (CWE-347) in the SSH server that lets an attacker who knows a username and key modulus forge signatures and open an SSH command channel as that user without the private key; CVE-2026-86060, an argument injection flaw (CWE-88) — described by CSO Online as exploitation of special-character username handling — that escalates privileges to root by manipulating the trusted RouterOS policy mask; and CVE-2026-67277, a missing-authentication flaw (CWE-306) in the bandwidth-test (btest) service enabling sensitive information disclosure that GBHackers reports can expose kernel memory and cause denial of service. CERT Polska confirmed the chained MikroTrick exploitation (CVE-2026-67276 followed by CVE-2026-86060) is being used to take full control of RouterOS devices with internet-exposed SSH; Shadowserver Foundation scans found over 122,500 devices with internet-reachable SSH, concentrated in Brazil, the US, and Indonesia. On September 10, 2026, CISA added CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities catalog, setting a September 13 mitigation deadline for federal agencies and designating CVE-2026-86060 as requiring forensic triage under Binding Operational Directive 26-04. Canada's Cyber Centre issued alert AL26-020 urging prioritization of internet-exposed SSH systems. Recommended mitigations include restricting SSH to trusted IPs or VPN, disabling SSH/WWW/bandwidth-test services, rotating keys and passwords, and reviewing logs for MikroTik 'Flagged' compromise indicators — noting that 'Flagged' status signals possible compromise but does not guarantee a device is clean. Suspected-compromised devices should be isolated, backed up, factory reset, and reconfigured from a clean file; compromised routers could have altered routing rules, persistence, traffic interception, or be used as pivots into internal networks.

  • MikroTik patched six RouterOS vulnerabilities found by CERT Polska; fixed versions: RouterOS 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21
  • MikroTrick chain: CVE-2026-67276 (SSH RSA public-key validation / signature verification flaw, CWE-347) enables authentication without the private key; CVE-2026-86060 (argument injection, CWE-88) escalates to root via special-character…
  • CVE-2026-67277 (missing authentication, CWE-306) in the bandwidth-test (btest) service enables sensitive information disclosure, kernel memory exposure, and denial of service per GBHackers; Canada's Cyber Centre describes it as sensitive…
  • CERT Polska confirmed active in-the-wild exploitation of the chain against RouterOS devices with SSH exposed to the internet
  • Shadowserver Foundation scans show over 122,500 devices with internet-reachable SSH, concentrated in Brazil, the US, and Indonesia
  • CISA added CVE-2026-67277 and CVE-2026-86060 to the KEV catalog on September 10, 2026, with a September 13, 2026 mitigation deadline for federal agencies
  • Under BOD 26-04, CISA requires forensic triage for CVE-2026-86060, meaning organizations must hunt for compromise indicators, not just patch
  • Canada's Cyber Centre issued alert AL26-020 covering all three CVEs and urging prioritization of internet-exposed SSH systems

Coverage timeline

  1. · 6d ago
    CSO Online· 82
    MikroTik patches flaws currently being exploited to take over routers

    MikroTik patches six RouterOS flaws, including the actively exploited MikroTrick SSH chain (CVE-2026-67276, CVE-2026-86060) enabling unauthenticated full router takeover.

  2. · 5d ago
    Canadian Centre for Cyber Security· 72
    AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

    Canada's Cyber Centre warns of three exploited MikroTik RouterOS vulnerabilities affecting SSH-exposed devices; CISA added two to its KEV catalog.

  3. · 4d ago
    GBHackers· 78
    CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

    CISA added two actively exploited MikroTik RouterOS flaws, CVE-2026-67277 and CVE-2026-86060, to its KEV catalog with a September 13 mitigation deadline.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-67276
SSH RSA Authorized-Key Bypass in MikroTik RouterOS 7.x

MikroTik RouterOS 7.x fails to compare the complete RSA public key when matching an SSH authentication attempt against an authorized user key, checking the key type and modulus but omitting the exponent. Because RouterOS verifies the signature against the client-supplied key, an attacker who knows the modulus of an authorized RSA key can present a key with exponent 1 and a forged signature and be accepted as that user without possessing the private key. Successful exploitation opens an SSH command channel as the target user, giving the attacker control of the router without a password or key. Only the RouterOS 7.x branch is affected, with fixes released in 7.23.4 (Long-term) and 7.24.2 (Stable). A public proof-of-concept is available and related reporting describes active campaigns hijacking MikroTik routers using chained RouterOS flaws, though this CVE is not in CISA KEV and its 30-day EPSS probability is low (0.2%).

Do: Upgrade affected devices to RouterOS 7.23.4 (Long-term) or 7.24.2 (Stable) or later. Until patched, restrict SSH access to trusted management networks and, if feasible, remove or replace RSA authorized keys with other key types. Check devices for signs of compromise highlighted in recent reporting, such as an unexpected SSH user named '-2'.

9.2<1%
  • MikroTik RouterOS 7.x branch prior to 7.23.4 (Long-term) and 7.24.2 (Stable)
mass~1M RouterOS 7.x devices (installed base in the millions; hundreds of thousands internet-exposed, with SSH a standard management service)
CVE-2026-86060
+1 in the same advisory: …67277
Argument-Injection Flaw in MikroTik RouterOS SSH Login Enables Privilege Escalation

CVE-2026-86060 is an argument-injection flaw (CWE-88) in MikroTik RouterOS's SSH login path: when a login supplies a username beginning with a prohibited character, the RouterOS login helper mishandles the argument, allowing the trusted RouterOS policy mask to be changed and privileges to be escalated. An unauthenticated attacker only needs the ability to reach the router's SSH service, since exploitation happens during the SSH login process itself. By altering the policy mask the attacker gains elevated rights on the device, and news reports indicate attackers have used this technique — including logins with usernames such as '-2' — as part of chains that take over routers without needing a password. Any RouterOS deployment running versions before the fixes (6.49.21 Long-term, 7.23.4 Long-term, 7.24.2 Stable) with SSH enabled or reachable is affected, with internet-exposed SSH at highest risk. Multiple outlets report the RouterOS flaws are being actively exploited in the wild, although no public proof-of-concept is known and the flaw is not yet in CISA KEV.

Do: Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable) as applicable. Until patched, restrict SSH (TCP 22) to trusted management networks or disable the SSH service if unused, and review authentication logs and user/group policy settings for tampering — reports indicate attackers log in with usernames beginning with '-' (e.g., '-2').

9.2
group max
1% KEV PoC ×2
  • MikroTik RouterOS v6 (Long-term channel) versions prior to 6.49.21 (fixed in 6.49.21)
  • MikroTik RouterOS v7 (Long-term channel) versions prior to 7.23.4 (fixed in 7.23.4)
  • MikroTik RouterOS v7 (Stable channel) versions prior to 7.24.2 (fixed in 7.24.2)
mass≈1M+ devices: hundreds of thousands to over a million RouterOS devices are routinely observed internet-exposed, and far more expose SSH to the LAN