Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers exploit MikroTik RouterOS flaws to hijack routers

Hackers are exploiting a chain of two vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.

The first flaw, tracked as CVE-2026-67276, is an SSH authentication bypass in MikroTik RouterOS caused by incomplete validation of RSA public keys. An attacker who knows a username and the public modulus of that user’s key can craft a different key and log in without the legitimate private key.

The second flaw, CVE-2026-86060, is an SSH privilege-escalation vulnerability caused by improper handling of specially crafted usernames. Attackers can manipulate an SSH session to obtain full administrative privileges.

Poland’s CERT agency discovered both flaws with help from GPT-5.5-cyber and GPT-5.6-sol. The agency named the exploit chain “MikroTrick” and said it is actively exploited in the wild.

A third issue, CVE-2026-67277, affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or remotely crash or restart a router.

MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3. The updates add startup checks for known signs of unauthorized configuration changes, disable malicious entries, and log a critical warning.

As of September 5, The ShadowServer Foundation counted 122,500 MikroTik devices with an exposed SSH interface. The exact number vulnerable to the exploit was not determined.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.