Feed›Vulnerability›Hackers exploit new MikroTik RouterOS flaws to hijack router...
VulnerabilityBleeping Computer
9.0 — CRITICAL

Hackers exploit new MikroTik RouterOS flaws to hijack routers

📅 7 September 2026 at 10:32 UTC📰 Bleeping ComputerView original source ↗
Hackers exploit new MikroTik RouterOS flaws to hijack routers

Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Hackers are exploiting two vulnerabilities in MikroTik RouterOS to hijack routers with exposed SSH services, resulting in potential full control of the device. The Polish CERT agency has confirmed that the exploit chain is actively being used in the wild.

⚙️Technical Details
CVEs
CVE-2026-67276CVE-2026-86060CVE-2026-67277Affected Systems: MikroTik RouterOSAttack Vectors: SSH authentication bypass and privilege escalation
Affected Systems
MikroTik RouterOS
Attack Vectors
SSH authentication bypass and privilege escalation
💥Impact Assessment
Severity: Critical
Who Is at Risk
MikroTik devices with exposed SSH interfaces, particularly those in public networks
🛡️Recommended Actions
1Restrict or disable externally accessible SSH, WWW/WWW-SSL, and bandwidth-test services
2Avoid using built-in SSH clients and outbound TLS connections over untrusted networks
3Isolate the router, preserve logs and configuration, then factory-resetting the device and rebuilding it from a trusted configuration
📦Affected Products
MikroTik RouterOS
🔐NVD Verified DataVERIFIED
Weaknesses
CWE-347
Weaknesses
CWE-88
Weaknesses
CWE-306

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed