CERT Polska Warns of Active Exploitation of MikroTik RouterOS Flaws

CERT Polska has confirmed active attacks against unpatched MikroTik routers with publicly accessible SSH. A chain of flaws allows attackers to gain administrator privileges without standard authentication.

The MikroTrick in RouterOS chain is, according to CERT Polska, being actively exploited against MikroTik devices with SSH services accessible from public networks. Attackers combine two vulnerabilities to gain full administrative control over the router without standard authentication. CERT Polska has recorded successful attacks since at least September 2, 2026.

The September 5 notice concerns RouterOS versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2. MikroTik has already released fixes, and CERT Polska confirmed that they block the observed attacks.

MikroTrick in RouterOS Combines Two Flaws

The observed chain includes the CVE-2026-67279 vulnerability, which allows an unauthorized SSH session to be opened. The attacker then exploits CVE-2026-86060 to escalate privileges through a specially crafted username. The result is administrator access without standard authentication.

The attacks described require a publicly accessible SSH service. The greatest immediate risk therefore affects devices whose management interfaces are exposed to untrusted networks and that have not yet been updated.

Fixed Versions and Recommended Steps

MikroTik released security fixes in RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25beta3. Administrators should update devices to the appropriate fixed release and simultaneously restrict access to management services to trusted addresses or networks only.

An update alone may not be enough to rule out a previous breach. CERT Polska lists SSH login records using the username “-2” and an unexpected privileged account named “ops” among the indicators of compromise. Administrators should therefore check system logs, user accounts, and the router’s configuration.

After updating, RouterOS may use the “Flagged” status to mark selected suspicious configuration changes and may disable them. MikroTik, however, warns that the absence of this flag does not prove that a device was not compromised. When suspicious findings are detected, it is advisable to isolate the device, preserve available evidence, restore it from a trusted configuration, and replace the secrets in use.

The Scope of the Attacks Is Not Yet Known

CERT Polska has not confirmed the number of affected devices or the attackers’ identity. The IP addresses listed in the alert serve as indicators of observed attacks or attempts, but by themselves do not confirm a connection to a specific group or state.

It has also not been confirmed whether attackers in this campaign are exploiting additional RouterOS flaws beyond the MikroTrick in RouterOS chain. Further technical information from MikroTik, new indicators of compromise, and potential independent data on the campaign’s scope will be important.

Sources

Verified and updated: 09/06/2026 15:24

Sharing