SPOJENO AI KEV ✓ EPSS 0.01
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]
MikroTik veřejná správa CA US FI NL HR SK CZ IT PL
CVE v události 6
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-67276 | 9.2 4.0 · CERT-PL | – | 0.00 |
| CVE-2026-67277 | 8.8 4.0 · CERT-PL | KEV ✓ | 0.01 |
| CVE-2026-67278 | 6.3 4.0 · CERT-PL | – | 0.00 |
| CVE-2026-67279 | 6.9 4.0 · CERT-PL | – | 0.00 |
| CVE-2026-67281 | 8.7 4.0 · CERT-PL | – | 0.00 |
| CVE-2026-86060 | 9.2 4.0 · CERT-PL | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.2.
Jak se o tom psalo 16
-
· Cyber Centre Kanada CA
AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
Number: AL26-020Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber…
-
· CISA Advisories US
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational…
-
· CISA KEV US
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability (CVE-2026-67277)
CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog. Affected product: MikroTik RouterOS. Remediation due date: 2026-09-13.
-
· CISA KEV US
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability (CVE-2026-86060)
CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog. Affected product: MikroTik RouterOS. Remediation due date: 2026-09-13.
-
· NCSC-FI FI
Actively exploited MikroTik RouterOS zero-day vulnerability
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.2, CVEs: CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060, CVE-2026-67277, CVE-2026-67276, Summary: MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. There is evidence that these vulnerabilities are under active exploitation. This is an important security update. Most configurations are not at risk, but upgrading is highly…
-
· Cyber Centre Kanada CA
Mikrotik security advisory (AV26-887)
Serial Number: AV26-887Date: September 8, 2026 As of September 5, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available…
-
· Malwarebytes Labs US
MikroTik router flaws allow takeover without a password
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…
-
· NCSC-NL NL
NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS
MikroTik heeft meerdere kwetsbaarheden verholpen in RouterOS. De eerste kwetsbaarheid betreft een fout in de SSH-authenticatiemechanisme waarbij de exponent van RSA-sleutels niet werd geverifieerd. Hierdoor kunnen aanvallers RSA-handtekeningen vervalsen en ongeautoriseerde SSH-toegang verkrijgen. De tweede kwetsbaarheid betreft een probleem met gebruikersnamen die beginnen met een verboden teken, waardoor de trusted policy mask kan worden gemanipuleerd en privilege escalation mogelijk is binnen…
-
· CERT.hr HR
Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja.
Poljski CERT (CERT Polska) identificirao je i koordinirao objavu šest ranjivosti u sustavu MikroTik RouterOS. Kombinacijom dviju od njih (CVE-2026-67276 i CVE-2026-86060), nazvanom “MikroTrick”, napadač može bez autentikacije preuzeti potpunu kontrolu nad uređajem ako je na njemu omogućen udaljeni pristup putem SSH protokola. Potvrđeno je da se ova kombinacija ranjivosti aktivno iskorištava u napadima na RouterOS uređaje dostupne s interneta, a napadi traju najmanje od 2. rujna 2026. Objavljene…
-
· SK-CERT (NBÚ SR) SK
VAROVANIE: Útočníci aktívne zneužívajú zraniteľnosti MIKROTIK smerovačov
Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred útokmi na smerovače značky MikroTik. Útočníci zreťazením bezpečnostných zraniteľností operačného systému MikroTik RouterOS dokážu získať úplnú kontrolu nad zariadením bez potreby autentifikácie. MikroTik routre sú sieťové zariadenia vyrábané spoločnosťou MikroTik a využívajú vlastný operačný systém RouterOS. Využívané sú poskytovateľmi internetových služieb, v komerčnej sfére a rovnako aj v domácnostiach.... The post VAROVANIE:…
-
· BleepingComputer US nadpis události
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]
-
· NÚKIB CZ
Upozornění na zranitelnost ve firmware RouterOS v zařízeních MikroTik
Upozorňujeme na zranitelnost ve firmware RouterOS v zařízeních MikroTik, kterou lze před autentizací zneužít k vzdálenému spuštění kódu s administrátorskými oprávněními. Aktuálně dochází k masovému zneužití této zranitelnosti. Dne 4. září 2026 byla vydána aktualizace RouterOS, v současnosti jsou však na internetu v ČR stále vystaveny tisíce zranitelných zařízení. Útočníci navíc u napadených zařízení upravují konfiguraci, aby si zajistili trvalý přístup k zařízení, který přežije jakoukoli…
-
· SANS Internet Storm Ctr. US
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. The patch will attempt to detect compromise and set the "Flagged" status. Details: https://mikrotik.com/supportsec/september-2026-vulnerability -- Johannes B. Ullrich, Ph.D. , Dean of…
-
· CSIRT Itálie (ACN) IT
MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità
MikroTik ha rilasciato aggiornamenti di sicurezza al fine di correggere 6 nuove vulnerabilità, di cui 2 con gravità “critica” e 2 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attivo in rete delle vulnerabilità CVE-2026-67276 e CVE-2026-86060, che potrebbero consentire ad un utente malintenzionato di eludere i meccanismi di autenticazione e di elevare i propri privilegi sui sistemi interessati.
-
· CERT Polska PL
Vulnerabilities in Mikrotik RouterOS software
CERT Polska has found 6 vulnerabilities (from CVE-2026-67276 to CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060) in Mikrotik RouterOS software.
-
· CERT Polska PL
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.