Active vulnerability exploitation in the MikroTik RouterOS operating system

10. September 2026
Critical

Six vulnerabilities have been identified in the MikroTik RouterOS operating system, three of which are classified as critical:

  • CVE-2026-67276 (CVSS 9.2)
  • CVE-2026-86060 (CVSS 9.2)
  • CVE-2026-67277 (CVSS 8.8)

By combining the exploitation of vulnerabilities CVE-2026-67276 and CVE-2026-86060, an attacker can gain full control over the device without prior authentication, provided that access to the SSH service via the Internet is enabled.

The vulnerabilities affect the SSH server and client, the bandwidth-test service, X.509 certificate processing and the WebFig interface, while patches are available in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.

The National CERT recommendations are:

  • update RouterOS to the appropriate version in which the listed vulnerabilities have been resolved;
  • if the update cannot be performed immediately, restrict access to SSH, WWW/WWW-SSL and bandwidth-test services so that they are accessible only from trusted networks;
  • after updating, check system logs, the "Flagged" status and the device configuration, including user accounts, scripts and any unauthorized changes;
  • in the event of suspected compromise, preserve logs and configuration data prior to remediation and notify the National CERT.

More details at:

https://mikrotik.com/supportsec/september-2026-vulnerability

https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/

The website www.cert.rs uses cookies for improvement of user experience and website functionality. By continuing to browse this website, you agree to the use of cookies.

Details