MikroTik RouterOS SSH Flaws Enable Full Device Hijack
CERT Polska discovered six RouterOS vulnerabilities, two of which allow unauthenticated full device control via SSH.

Attackers exploit a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH exposed to the internet, CERT Polska found.
CERT Polska, Poland’s national CSIRT team, discovered six vulnerabilities in RouterOS and coordinated disclosure with MikroTik. Two combined flaws enable full device control without authentication when SSH is accessible from the internet, identified as the MikroTrick exploit chain.
“In recent days we have been observing attacks against RouterOS devices accessible from the internet.” the CERT Polska team wrote.
“It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately,” they added.
The vulnerabilities were discovered using the GPT-5.5-cyber and GPT-5.6-sol models through OpenAI’s Government and Trust Agency Collaboration program.
“At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check),” the Shadowserver Foundation posted on Mastodon.
One flaw, CVE-2026-67276 (CVSS 9.2), bypasses SSH authentication by comparing only the public modulus of a user’s RSA key instead of the entire key, allowing an attacker with a username and modulus to forge a key and log in.
CVE-2026-86060 (CVSS 9.2) is a privilege escalation flaw in how RouterOS handles SSH usernames beginning with a disallowed character, enabling a crafted username to gain full administrative privileges.
A third flaw, CVE-2026-67277 (CVSS 8.8), affects the bandwidth-test service, allowing unauthenticated connections to reach logged-in states, with additional memory leak and integer underflow issues that could expose kernel memory or crash the device.
Three lower-severity flaws affect the SSH client, X.509 certificate handling, and the WebFig interface.
Indicators of compromise include login failures for user -2 from via ssh, user additions via ssh:-2@, and unexplained appearance of a highly privileged user named “ops”.
Attacks were traced to IP 82.192.72.4, active since at least September 2, and a second address, 103.102.31.18, was flagged for exploitation attempts.
MikroTik released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, stating the update is highly recommended despite most configurations not being immediately at risk.
“This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.” MikroTik noted.
“For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade,” they added.
The patched versions include a startup configuration scan that detects unauthorized changes, disables suspicious entries, logs warnings, and sets a “Flagged” marker.
“Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise,” MikroTik advised.
CERT Polska recommends updating to 7.25beta3, 7.24.2, 7.23.4, or 6.49.21, then checking logs for compromise messages and flagged markers via the /system/device-mode/print command, and reviewing configurations for unknown users or scripts.
If immediate patching is impossible, CERT Polska advises disabling SSH, WWW/WWW-SSL, and bandwidth-test services, or restricting them to trusted networks, and avoiding untrusted network connections.
“These are only temporary measures that reduce the attack surface. They do not replace installing the patched RouterOS version,” they concluded.
The findings were published on an accelerated schedule as patched packages are public, and community analysis has allowed reconstruction of fixed bugs without releasing exploit code.
“We limit the description to the information administrators need and do not publish exploit code or details that would make automating attacks easier,” they concluded.





