CERT Polska Warns of Active Exploitation of MikroTik RouterOS Flaws
CERT Polska has confirmed active attacks against unpatched MikroTik routers with publicly accessible SSH. A chain of flaws allows attackers to gain administrator privileges without standard authentication.

The MikroTrick in RouterOS chain is, according to CERT Polska, being actively exploited against MikroTik devices with SSH services accessible from public networks. Attackers combine two vulnerabilities to gain full administrative control over the router without standard authentication. CERT Polska has recorded successful attacks since at least September 2, 2026.
The September 5 notice concerns RouterOS versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2. MikroTik has already released fixes, and CERT Polska confirmed that they block the observed attacks.
MikroTrick in RouterOS Combines Two Flaws
The observed chain includes the CVE-2026-67279 vulnerability, which allows an unauthorized SSH session to be opened. The attacker then exploits CVE-2026-86060 to escalate privileges through a specially crafted username. The result is administrator access without standard authentication.
The attacks described require a publicly accessible SSH service. The greatest immediate risk therefore affects devices whose management interfaces are exposed to untrusted networks and that have not yet been updated.
Fixed Versions and Recommended Steps
MikroTik released security fixes in RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25beta3. Administrators should update devices to the appropriate fixed release and simultaneously restrict access to management services to trusted addresses or networks only.
An update alone may not be enough to rule out a previous breach. CERT Polska lists SSH login records using the username “-2” and an unexpected privileged account named “ops” among the indicators of compromise. Administrators should therefore check system logs, user accounts, and the router’s configuration.
After updating, RouterOS may use the “Flagged” status to mark selected suspicious configuration changes and may disable them. MikroTik, however, warns that the absence of this flag does not prove that a device was not compromised. When suspicious findings are detected, it is advisable to isolate the device, preserve available evidence, restore it from a trusted configuration, and replace the secrets in use.
The Scope of the Attacks Is Not Yet Known
CERT Polska has not confirmed the number of affected devices or the attackers’ identity. The IP addresses listed in the alert serve as indicators of observed attacks or attempts, but by themselves do not confirm a connection to a specific group or state.
It has also not been confirmed whether attackers in this campaign are exploiting additional RouterOS flaws beyond the MikroTrick in RouterOS chain. Further technical information from MikroTik, new indicators of compromise, and potential independent data on the campaign’s scope will be important.
Sources
- CERT Polska — Critical vulnerabilities in MikroTik RouterOS are being actively exploited – Confirms active exploitation of the chain against publicly accessible SSH, the date going back at least to September 2, indicators of compromise, and recommended mitigations.
- CERT Polska — Vulnerabilities in MikroTik RouterOS software – Provides the technical conditions for CVE-2026-67279 and CVE-2026-86060, vulnerable version ranges, and fixed releases.
- MikroTik — September 2026 vulnerability – Confirms the release of security updates for all RouterOS channels and the post-update compromise-check procedure.
- MikroTik Documentation — Device-mode – Explains the meaning of the “Flagged” status, its limitations, and the need for a full configuration audit when a device is flagged.
Verified and updated: 09/06/2026 15:24



