CERT Polska discloses six MikroTik RouterOS vulnerabilities including critical SSH bypass

CERT Polska discloses six MikroTik RouterOS vulnerabilities including critical SSH bypass

CERT Polska disclosed six MikroTik RouterOS vulnerabilities on September 5, including critical SSH authentication bypass flaws actively exploited in the wild.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Sep 08, 2026

CERT Polska disclosed six vulnerabilities in MikroTik RouterOS on September 5, 2026. Two of them chain together to allow unauthenticated attackers to gain full administrative access on devices with SSH exposed to the internet.

The flaws and how they work

The advisory details CVE-2026-67276 (CVSS 9.2), an SSH authentication bypass that stems from incomplete verification of RSA public keys. An attacker who knows a valid username and the modulus of an authorized key can authenticate by supplying a key with exponent 1. CVE-2026-86060 (also CVSS 9.2) permits privilege escalation through crafted usernames that exploit argument injection. Together they enable remote takeover without credentials on exposed management interfaces.

Additional issues affect the bandwidth-test service, X.509 certificate validation, SSH session handling, and WebFig file access. Vulnerable versions span multiple branches; patches arrived in 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.

Active exploitation and scale

Attackers began chaining the SSH flaws at least as early as September 2. Scans at the time showed more than 122,500 MikroTik devices reachable on port 22. CERT Polska observed specific log patterns and the creation of a privileged user named “ops” in confirmed incidents. MikroTik added a new “Flagged” device-mode indicator to help administrators detect post-compromise changes.

Practical steps for operators

  • Update RouterOS immediately to a patched release.
  • After updating, review logs, the flagged marker, and configuration for unknown users, scripts, or tunnels.
  • Where patching is delayed, restrict SSH, WWW, and bandwidth-test access to trusted networks only.
  • If compromise is suspected, isolate the device, preserve evidence, and perform a factory reset followed by clean reconfiguration.

MikroTik devices appear in ISP edge routers, small office networks, and industrial setups. Exposed management services remain a common misconfiguration that turns routine software flaws into persistent footholds.

Why this matters now

Network infrastructure has historically received slower patch cycles than servers and endpoints. The combination of high-severity remote flaws, confirmed in-the-wild exploitation, and the sheer number of exposed devices makes this disclosure a priority for any organization running MikroTik hardware. Administrators should treat router and switch updates with the same urgency applied to critical servers, because these devices often sit at the perimeter and retain access even after other systems are rebuilt.

Sources

Cover photo by Pascal 📷 on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...