MikroTik patched six vulnerabilities in RouterOS releases earlier than 6.49.21, 7.23.4, and 7.24.2. CERT Polska reported flaws affecting SSH authentication and RSA signature validation, WebFig file access, the btest service, and SSH login privilege handling. The issues can permit unauthenticated remote SSH command execution, disclosure of root-owned files that may contain credentials, kernel restarts, privilege escalation, and TLS server impersonation.
Organizations running affected RouterOS branches should upgrade immediately to RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable). Administrators should review RouterOS flagged status and logs for compromise evidence, and investigate unauthorized accounts, scripts, scheduled tasks, firewall, VPN, DNS, NAT, and other configuration changes, particularly on internet-exposed devices.

See affected versions and whether adversaries are exploiting it.
18 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published Alert AL26-020 on vulnerabilities CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060 affecting MikroTik RouterOS. It urged immediate upgrades, prioritization of internet-exposed SSH devices, and review of logs and network activity for compromise indicators.
CISA added CVE-2026-67277 and CVE-2026-86060, two actively exploited MikroTik RouterOS vulnerabilities, to its Known Exploited Vulnerabilities catalog. The additions reinforce the need to prioritize patching, especially for internet-exposed SSH services.
The Canadian Centre for Cyber Security issued advisory AV26-887, stating that CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060 in MikroTik RouterOS are being exploited in the wild. It advised administrators to review vendor information and apply available updates.
Shadowserver Foundation scans identified more than 122,000 MikroTik devices with SSH enabled and exposed to the internet. These devices were potentially reachable by attackers exploiting the actively abused MikroTrick SSH vulnerability chain.
CERT Polska published coordinated disclosure details for six MikroTik RouterOS flaws: CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060. The disclosed issues include unauthenticated SSH command execution, WebFig file disclosure, btest information disclosure and kernel restart, TLS impersonation, and SSH privilege escalation.
MikroTik released RouterOS 7.23.5, identified as a patched version for the MikroTrick SSH vulnerabilities, following the September 3 releases for other supported branches.
Tenable published the `mikrotik_6_49_21.nasl` Nessus plugin to identify MikroTik RouterOS systems below fixed versions, covering CVE-2026-67277, CVE-2026-67279, and CVE-2026-86060. The plugin uses the RouterOS version knowledge-base item and supports an optional thorough-check setting.
Around 08:00 UTC on September 2, a MikroTik administrator reported that an SSH connection from 82.192.72.4 was followed by creation of rogue "0" and "ops" accounts. The "ops" account had write and policy permissions, and the administrator considered a full netinstall necessary to ensure the device was clean.
Successful attacks exploiting internet-exposed MikroTik RouterOS SSH services were reported to date back to at least September 2. The attacks enabled unauthenticated attackers to obtain full administrative control of affected routers.
A public proof of concept for the RouterOS SSH RSA public-key authentication-bypass vulnerability CVE-2026-67276 was released for controlled laboratory testing.
MikroTik added a mechanism to updated RouterOS software that scans devices for known indicators of compromise. Devices in which indicators are detected are assigned a “flagged” status.
Additional investigation details identified `ssh:-2@<IP>` entries in RouterOS system history as a confirmed-compromise artifact when tied to configuration changes, and listed 103.102.31.18 as another indicator. The report also provided SHA-256 hashes for ftpsrv.py, launch.sh, serve.py, and BusyBox files reportedly hosted on 82.192.72.4.
CERT Polska confirmed active exploitation of the MikroTrick chain, which combines CVE-2026-67276 and CVE-2026-86060 to let unauthenticated attackers obtain full administrative control of internet-exposed RouterOS devices with SSH enabled. Observed attacks included failed SSH logins for user "- 2" and creation of users through SSH, with a privileged "ops" account identified as an additional compromise indicator.
Technical details for CVE-2026-67277 showed that RouterOS btest accepts a related connection before the primary session completes authentication. An unauthenticated client can trigger transmission of uninitialized kernel packet-buffer data via an IPv4 UDP test, while an inverted packet-size check can cause unsigned underflow, oversized fragmented output, and a RouterOS kernel restart.
Technical analysis of CVE-2026-67281 described an unauthenticated WebFig /jsproxy file-read issue in which a stale, uninitialized session principal pointer can be used during authorization checks. Attackers can manipulate allocator state and use parent-directory components in encrypted URIs to escape the WebFig namespace and read root-owned files, including credential-containing configuration stores.
Technical details for CVE-2026-86060 identified an argument-handling flaw in the RouterOS SSH login path. An unauthenticated attacker able to reach the login helper can use a username beginning with a prohibited character to alter the trusted RouterOS policy mask and escalate privileges.
Technical details for CVE-2026-67276 showed that RouterOS SSH public-key authentication matches RSA keys by type and modulus but does not compare the exponent. An attacker who knows an authorized key's modulus can submit an exponent-one key, forge a signature, and establish an SSH command channel as the authorized user without the private key.
MikroTik issued important security updates for supported RouterOS branches, fixing affected versions through 6.49.21, 7.23.4, and 7.24.2. The vendor initially withheld technical details and stated that most configurations were not at risk.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
49 references tracked. Mallory keeps watching after this page renders.
triskelelabs.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcetenable.com
Open sourceforum.mikrotik.com
Open sourcemikrotik.com
Open sourcereddit.com
Open sourcemikrotik.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.