CERT Polska says two MikroTik RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, can be chained to give attackers full administrative control of Internet-exposed routers without a password or completed authentication. Evidence of exploitation appeared before patches were released, with logs showing the suspicious SSH username -2 and post-exploitation activity tied to accounts like ops. #MikroTik #RouterOS #CVE-2026-67279 #CVE-2026-86060 #CERTPolska #CISA
Keypoints
- Two RouterOS SSH flaws can be chained to gain full admin access.
- CVE-2026-67279 bypasses normal SSH authentication flow.
- CVE-2026-86060 enables argument injection in the login process.
- Attack logs show exploitation attempts using the username -2.
- Administrators should patch, inspect devices, and rebuild compromised systems.
Read More: https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html