Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers
Hackers are exploiting two vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
Intelligence analysis by Qwen 2.5 (3B)

Hackers are using two vulnerabilities in MikroTik routers to hijack devices with exposed SSH services.
Hackers found two ways to trick MikroTik routers into letting them control the devices. One way is by pretending to be someone else who knows a router's login details. The other way is by tricking the router into giving them full control over it.
Analysis
{"heading_1":"CVE-2026-67276: SSH Authentication Bypass Flaw","paragraph_1":"CVE-2026-67277 affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to remotely crash/restart the router.","paragraph_2":"MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3.","paragraph_3":"The updates add a compromise-detection mechanism to the routers that looks for known signs of unauthorized configuration changes at startup, disables malicious entries, and logs a critical warning.","heading_2":"CVE-2026-86060: SSH Privilege Escalation Flaw","heading_3":"Additional Flaw: CVE-2026-67277","paragraph_4":"However, the CERT notes that the absence of a marker indicating compromise should not be taken as a guarantee that a router has not been compromised."}
Key points
- Hackers are exploiting two vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
- CVE-2026-67276 is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys.
- CVE-2026-86060 is an SSH privilege escalation flaw in MikroTik RouterOS due to improper handling of specially crafted usernames.
- CVE-2026-67277 affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to remotely crash/restart the router.
- MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3.
By fixing the vulnerabilities, MikroTik can prevent attackers from taking control of their routers.
Even with the fixes, attackers might still find ways to exploit the vulnerabilities, so users need to be cautious and keep their routers updated.



