MikroTik Patches Three Critical RouterOS Flaws Including SSH Auth Bypass
MikroTik released a security update in September 2026 addressing three critical RouterOS vulnerabilities, flagged by India's CERT-In as advisory CIVN-2026-0460. The most severe flaw allows unauthenticated attackers to bypass SSH login entirely by sending a forged RSA key, potentially granting full administrative control. A second SSH vulnerability enables privilege escalation by manipulating argument delimiters in the login path, allowing attackers to alter router policy and pivot to internal networks. A third flaw in the bandwidth-test service exposes uninitialized kernel memory to unauthenticated network requests and can crash the device. Affected users are urged to upgrade to the patched RouterOS versions and, in the interim, restrict SSH access to trusted sources and disable the bandwidth-test service where not needed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in