Active Exploits Target MikroTik Routers Following Critical SSH Vulnerability Disclosures

MikroTik initially withheld technical details about the vulnerability, saying it wanted to give administrators time to install updates before attackers could reverse-engineer the flaw from public disclosure.
Reverse-engineering discussions on MikroTik’s official support forum indicated that the issue affects a core library used by multiple RouterOS services. Researchers said an unauthenticated attacker could obtain direct shell access regardless of whether the device used password-based or SSH key-based authentication.
The six vulnerabilities disclosed by CERT Polska span more than SSH: the affected RouterOS components also include bandwidth testing, X.509 certificate handling and the WebFig management interface.
Latvia’s national CERT separately reported a marked increase in activity targeting MikroTik routers and urged both organizations and home users to update to MikroTik’s patched builds.
Attackers are actively hijacking MikroTik routers by exploiting a chain of two critical flaws in RouterOS that bypass authentication entirely. CERT Polska disclosed six vulnerabilities affecting internet-exposed SSH services, with active exploitation confirmed since at least September 2, 2026. MikroTik released emergency patches including RouterOS 7.24.2, 7.23.4, and 6.49.21, urging administrators to update immediately and restrict internet access to SSH.
CVE-2026-67276 bypasses RSA public-key authentication on RouterOS, while CVE-2026-86060 escalates the compromised session to full administrative access. Researchers note that attackers gain direct shell access without needing the legitimate private key, regardless of whether the device uses password or key-based authentication. The flaws affect a core library used across multiple RouterOS services.
Reverse-engineering discussions on MikroTik's official forum reveal that an unauthenticated attacker can obtain shell access to any exposed device. Logs show suspicious accounts created, including a reported "-2" user. Administrators must review device logs immediately for signs of compromise.
CERT Polska identified six RouterOS flaws spanning multiple components: SSH authentication, bandwidth testing, X.509 certificate handling, and the WebFig management interface. The vulnerabilities create multiple entry points for attackers. MikroTik released patched versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 to address all disclosed issues.
Latvia's national CERT reported a marked increase in attacks targeting MikroTik routers, warning both organizations and home users to update. The urgency reflects real-world exploitation: attackers have been actively compromising internet-exposed devices for weeks.
Administrators should take three immediate actions: restrict or disable internet-facing SSH access, install the appropriate patch version for their RouterOS build, and review logs for suspicious accounts and sessions. The "-2" user is a known indicator of compromise and requires investigation.
MikroTik initially withheld technical vulnerability details to give administrators time to patch before attackers could reverse-engineer the flaw from public disclosure. However, detailed discussions already appeared online. Any device with exposed SSH should be treated as potentially compromised until patched and logs are verified.
Publishers
15
Articles
7
Reach
22