CVE Tools
Back to feed
Exploited in the wild MikroTik RouterOS zero-day MikroTik network-edge

Hackers exploit new MikroTik RouterOS flaws to hijack routers

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Attackers are actively leveraging a combination of two recently disclosed vulnerabilities in MikroTik RouterOS to gain full administrative control over devices with SSH services exposed to the internet. The exploit chain involves CVE-2026-67276, an authentication bypass flaw stemming from incomplete RSA public key validation, and CVE-2026-86060, a privilege escalation bug triggered by specially crafted usernames. This threat was identified by Poland's CERT agency, which confirmed active in-the-wild exploitation under the name "MikroTrick." A related issue, CVE-2026-67277, also affects the bandwidth-test service, potentially allowing remote denial-of-service conditions.