MikroTik Patches Critical Flaws Chained to Hack Routers
Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited.
The exploited flaws, dubbed MikroTrick, allow attackers to bypass authentication and take over devices, CERT Poland warns.
In a scarce advisory, MikroTik warns of the identified security defects, recommends immediate patching, and directs users to CERT Polandâs advisory for additional information.
âThis is an important security update. Most configurations are not at risk,â MikroTik says. It also recommends blocking SSH access from untrusted sources, noting that compromised devices will have a âFlaggedâ entry in the log section.
CERT Poland, meanwhile, says it has received confirmation that two of the resolved vulnerabilities have been chained together to compromise devices.
âWe now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control of devices whose SSH service is accessible from public networks. According to the information we have, updating to the latest version prevents these attacks,â CERT Poland notes.
It highlights three vulnerabilities: CVE-2026-67276 (CVSS score of 9.2), an SSH authentication bypass bug; CVE-2026-86060 (CVSS score of 9.2), an SSH session privilege manipulation issue; and CVE-2026-67277 (CVSS score of 8.8), a memory disclosure and denial-of-service weakness.
CERT Poland says hackers have been chaining the MikroTrick bugs since at least September 2, creating an account named âopsâ. The attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18.
âThe presence of any of these artifacts indicates an attempt to exploit the vulnerabilities and must be investigated immediately; at the same time, the absence of the traces mentioned above does not rule out unauthorized activity,â CERT Poland notes.
Users are advised to update their MikroTik routers to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible.
The updates also resolve CVE-2026-67278 (enables TLS server impersonation), CVE-2026-67279 (allows unauthenticated attackers to tamper with files, including configuration files), and CVE-2026-67281 (allows attackers to disclose root-owned files, including configuration stores).
The Shadowserver Foundation found more than 120,000 MikroTik devices with SSH accessible from the internet during a 24-hour scan window on September 5.
Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX
Related: In Other News: Microsoftâs Cloud Patches, Hacked Dropbox Accounts, Guardioâs $1.1B Valuation
Related: Malicious Virtualizor Update Served via BGP Hijacking
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.