Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
CERT Polska uncovered six RouterOS vulnerabilities, including the MikroTrick chain that can give attackers full control of MikroTik devices with SSH exposed to the internet. MikroTik has released patched RouterOS versions, and administrators are urged to update immediately and check for signs of compromise such as the suspicious “ops” account and altered logs. #MikroTrick #RouterOS #CERTPolska #MikroTik #CVE-2026-67276 #CVE-2026-86060 #CVE-2026-67277

Keypoints

  • CERT Polska found six vulnerabilities in RouterOS and coordinated disclosure with MikroTik.
  • The MikroTrick chain can hijack MikroTik devices with SSH exposed to the internet.
  • CVE-2026-67276 enables SSH authentication bypass through RSA modulus comparison flaws.
  • CVE-2026-86060 allows privilege escalation to full administrative access.
  • MikroTik released fixes and urges immediate upgrades plus review for suspicious logs and unknown users.

Read More: https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/