discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers

Hackers are exploiting two vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.

By Bill Toulas·Sep 7·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers
Image: bleepingcomputer.com

Hackers are using two vulnerabilities in MikroTik routers to hijack devices with exposed SSH services.

Why it matters

This vulnerability could allow attackers to take control of MikroTik routers, posing a risk to internet security.

Hackers found two ways to trick MikroTik routers into letting them control the devices. One way is by pretending to be someone else who knows a router's login details. The other way is by tricking the router into giving them full control over it.

Analysis

{"heading_1":"CVE-2026-67276: SSH Authentication Bypass Flaw","paragraph_1":"CVE-2026-67277 affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to remotely crash/restart the router.","paragraph_2":"MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3.","paragraph_3":"The updates add a compromise-detection mechanism to the routers that looks for known signs of unauthorized configuration changes at startup, disables malicious entries, and logs a critical warning.","heading_2":"CVE-2026-86060: SSH Privilege Escalation Flaw","heading_3":"Additional Flaw: CVE-2026-67277","paragraph_4":"However, the CERT notes that the absence of a marker indicating compromise should not be taken as a guarantee that a router has not been compromised."}

Key points

  • Hackers are exploiting two vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
  • CVE-2026-67276 is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys.
  • CVE-2026-86060 is an SSH privilege escalation flaw in MikroTik RouterOS due to improper handling of specially crafted usernames.
  • CVE-2026-67277 affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to remotely crash/restart the router.
  • MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3.
The Upside

By fixing the vulnerabilities, MikroTik can prevent attackers from taking control of their routers.

The Downside

Even with the fixes, attackers might still find ways to exploit the vulnerabilities, so users need to be cautious and keep their routers updated.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityroutersshvulnerabilitymalware

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 7, 2026

Source

bleepingcomputer.com

Share

Topics

securityroutersshvulnerabilitymalware

Related

More from this desk

Sep 8·bleepingcomputer.com

220 Million Traveler Records Exposed in Vietnam-Linked API Leak

220 million traveler records exposed in a Vietnam-linked API leak, spanning 9 years of data from January 2017 to April 2026.

Sep 7·bleepingcomputer.com

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.

Sep 7·thehackernews.com

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.

Sep 7·bleepingcomputer.com

BigBear Microsoft 365 phishing service bypasses MFA at 258 organizations

Phishing-as-a-service framework BigBear 2.0 bypassed MFA at 258 organizations, stealing over 5,000 Microsoft 365 credentials.