top of page

Executive Security Advisory: MikroTik RouterOS – active attacks can lead to router takeover

Sep 8
2 min read

Management summary: CERT Polska confirms active attacks against MikroTik RouterOS. On devices whose SSH service is reachable from public networks, the combination of CVE-2026-67276 and CVE-2026-86060 can result in full router takeover. MikroTik has released fixed versions; exposed systems should be updated and investigated immediately.

What is MikroTik RouterOS? RouterOS is the operating system used on many MikroTik routers, firewalls and network gateways. These devices often sit at the boundary between the corporate network and the internet and handle routing, VPN, firewalling and administrative access.

What is happening? CVE-2026-67276 affects SSH authentication and can under specific conditions allow login without the legitimate RSA private key. CVE-2026-86060 uses a crafted username to escalate the SSH session to full administrative RouterOS privileges. CERT Polska reports real-world attacks chaining both flaws.

Who is most exposed? Priority should be given to RouterOS devices with SSH or other management services directly reachable from the internet. MikroTik notes that its default configuration blocks SSH from the internet, making manually exposed management ports particularly important to review.

Immediate actions: Upgrade RouterOS to a fixed release: 7.25beta3, 7.24.2, 7.23.4 or 6.49.21, or a newer vendor-approved version. If immediate patching is impossible, block SSH, WWW/WWW-SSL and bandwidth-test from all untrusted networks. After upgrading, review the Flagged status, logs and configuration for unknown users, scripts, scheduler entries, proxies and tunnels.

Compromise indicators: CERT Polska highlights log entries containing “login failure for user -2”, users added by “ssh:-2”, and a highly privileged account named “ops”. RouterOS Flagged status may provide additional evidence, but the absence of a flag does not prove the device is clean.

What to ask your IT provider: 1. Do we operate MikroTik/RouterOS devices with SSH or other management ports exposed to the internet? 2. Are all devices already on a fixed RouterOS release? 3. Have logs, Flagged status and configuration been actively reviewed for compromise?

Our assessment: High priority for internet-exposed MikroTik systems. Because active exploitation leading to complete device takeover is confirmed, patching, removing unnecessary internet exposure and compromise checks should not wait for the next routine maintenance window. Sources: CERT Polska, September 5, 2026; MikroTik Security Advisory, September 3, 2026.

 
 

Contact us

vNext GmbH, Patschär 7, 7306 Fläsch

Phone: +41 81 710 50 85

Ihr Profi für Websites und unbeschreibliches Foto Design
Ihr Partner für unvergessliche Events und Momente mit Ihren liebsten.
Wenn es Vertrauen braucht ist PSD Ihr Partner.

We work with the best partners

© 2023 by vNext GmbH

bottom of page