Vulnerabilities · 4h ago

MikroTik RouterOS Chain Enabled Unauthenticated Takeover

CERT Polska said MikroTik’s September 3 RouterOS patches covered two flaws, CVE-2026-67279 and CVE-2026-86060, that could be chained into full device takeover without authentication. The same disclosure says administrators were already seeing logs that looked like attacks in the wild before the details were public.

The chain starts with a crafted SSH username that changes how RouterOS passes arguments to its login program, then lets an attacker pivot into a privileged session and flip trusted policy state. In plain terms, the login path itself becomes the control plane, so a box that only exposes SSH management can still hand over routing and access functions.

For operators of MikroTik edge devices, the important point is that the blast radius is the device itself and whatever it brokers for the network. The disclosure also shows that holding back exploit details did not buy much time: patch-release day was enough for public reverse engineering, and the reports suggest exposure may already have existed before the fixes were available.

CVE-2026-86060

NVD KEV

Known exploited · CISA KEV

EPSS 1% (63rd percentile).

CISA federal remediation date Sep 13 · date passed

CVE-2026-67279

NVD KEV

EPSS 0.4% (38th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories