MikroTik RouterOS: CERT.PL discloses six CVEs; MikroTrick SSH chain actively exploited
MikroTik published an important RouterOS security update on 3–4 September 2026 (supportsec bulletin and forum notice) with details withheld, fixing builds 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21. On 5 September 2026 CERT Polska disclosed six coordinated CVEs and confirmed active exploitation. Highest-impact pair (CERT.PL CVSS 9.2 each): CVE-2026-67276 SSH authentication bypass (RouterOS did not fully compare RSA public keys, so an attacker who knew a username and the public modulus could craft another key and log in without the private key) and CVE-2026-86060 SSH session privilege manipulation via a crafted username that yields a full-admin session. CVE-2026-67277 (CVSS 8.8) is unauthenticated bandwidth-test memory disclosure/crash. CVE-2026-67281 (CVSS 4.0 8.7 per CVE record) is unauthenticated WebFig /jsproxy file read that can disclose root-owned config stores. CERT.PL also lists CVE-2026-67278 and CVE-2026-67279 on the CVE details page. CERT.PL says the MikroTrick combination of two SSH flaws is being used for full takeover of devices with SSH on public networks; successful attacks creating a privileged user named ops have been seen from 82.192.72.4 since at least 2 September 2026, with 103.102.31.18 used in exploit attempts. Log IoCs include login failure for user -2 via ssh and user <name> added by ssh:-2@<ip>. Fixed releases set a Flagged marker when known compromise traces are found (absence of Flagged is not clean). The Hacker News (6 September 2026) notes CERT.PL guidance to prefer 7.23.5 on the long-term 7.23 channel (after 7.23.4). Latvia's national CERT also reported increased MikroTik targeting and urged the same patched builds. Until patched: restrict SSH, WWW/WWW-SSL and bandwidth-test to trusted management nets; do not initiate TLS or built-in SSH clients from an unpatched box toward untrusted hosts. If Flagged or otherwise suspect: isolate, preserve logs/config, factory-reset and rebuild from a verified config, rotate secrets. Primary: CERT Polska active-exploitation advisory. UPDATE 10 September 2026: CISA added CVE-2026-86060 and CVE-2026-67277 to KEV (dateAdded 2026-09-10). Internet-exposed SSH / bandwidth-test paths remain the priority; patch and hunt Flagged / ops / ssh:-2 IoCs.
- Product
- MikroTik RouterOS
- Versions
- Vulnerable: 7.24 before 7.24.2; 7.0.0 before 7.23.4; 6.0.0 before 6.49.21. Fixed: 7.25 beta 3, 7.24.2, 7.23.4, 6.49.21 and newer
- CVSS
- (CVE-2026-67276 and CVE-2026-86060, CERT.PL); 8.8 (CVE-2026-67277); 8.7 (CVE-2026-67281, CVSS 4.0)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade to 7.25 beta 3 / 7.24.2 / 7.23.4 (prefer 7.23.5 on LTS) / 6.49.21+; check Flagged and logs for ops/-2 SSH artifacts; audit users/scripts/tunnels; if compromised: isolate, preserve evidence, factory-reset, rotate secrets
Primary: CERT Polska — RouterOS actively exploited (5 Sep 2026) · Vendor: MikroTik — September 2026 vulnerability bulletin · CVE: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, CVE-2026-67281, CVE-2026-67278, CVE-2026-67279 · CERT Polska — six RouterOS CVE details (5 Sep 2026)
