9,560 MikroTik Routers Expose SSH Globally Amid Two Actively Exploited Flaws
CERT Polska disclosed six MikroTik RouterOS vulnerabilities in September 2026, two of which — CVE-2026-67277 and CVE-2026-86060 — were already being actively exploited in combination to give unauthenticated attackers full administrative control. CISA added both flaws to its Known Exploited Vulnerabilities catalog on 10 September 2026. A ZoomEye scan identified over 8 million internet-visible RouterOS devices, of which 9,560 specifically expose SSH — the key precondition for the reported attack chain. Security researchers caution that these figures represent a floor, not a ceiling, since scanning coverage is incomplete and the fingerprint cannot distinguish patched from unpatched firmware. Organizations running RouterOS equipment are advised to audit internet-facing SSH exposure, verify firmware versions against patched releases, and review logs for signs of unauthorized access.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in