Critical MikroTik RouterOS Flaws Actively Exploited to Hijack Routers
Attackers are actively exploiting two critical vulnerabilities in MikroTik RouterOS, tracked as CVE-2026-67276 and CVE-2026-86060, to take full administrative control of internet-exposed routers. The attack chain first bypasses SSH authentication by exploiting incomplete RSA public key validation, requiring only the target username and public key modulus, then escalates privileges to full admin access via a crafted username. Once inside, attackers add administrative accounts and can alter DNS, VPN, routing, and firewall configurations, potentially enabling traffic interception and lateral movement into internal networks. CERT Polska published its advisory on September 5, 2026, warning that the absence of visible indicators does not confirm a device is clean. Administrators are urged to update RouterOS to versions 7.24.2, 7.23.4, 6.49.21, or later, restrict or disable exposed services, and fully rebuild any suspected compromised devices while rotating all credentials and keys.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in