Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
CERT Polska reported active exploitation of a vulnerability chain in MikroTik RouterOS that allows attackers to seize full control of devices with internet-exposed SSH services without prior authentication. The attack leverages CVE-2026-67276, an SSH authentication bypass, combined with CVE-2026-86060, a privilege escalation flaw, to establish administrative access. Additionally, CVE-2026-67277 was identified alongside three other lower-severity issues affecting certificate handling and web interfaces.
Vendors have released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Administrators are urged to apply these updates immediately, disable exposed services like SSH as a temporary mitigation, and audit device configurations for unauthorized users such as 'ops' or suspicious script entries.