Summary
Key Points:
- Critical vulnerabilities in MikroTik RouterOS, including SSH authentication bypass and privilege escalation, are being actively exploited, allowing attackers to take full control of affected devices.
- The impact is severe for any RouterOS device with SSH access exposed to the internet, leading to unauthorized access and potential compromise of sensitive configurations.
- Immediate updates to versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 are recommended to mitigate these vulnerabilities. Additionally, administrators should check for unauthorized users and configurations.
Technical Details: The vulnerabilities include CVE-2026-67276 (SSH authentication bypass) and CVE-2026-86060 (privilege manipulation via crafted usernames), both with a CVSS score of 9.2. Attackers have been confirmed to exploit these flaws since at least September 2, using IP addresses such as 82.192.72.4.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1203 - Exploit Public-Facing Application (Initial Access)
- T1069 - Permission Groups Discovery (Discovery)
IOCs Mentioned:
- IP Addresses: 82.192.72.4, 103.102.31.18
- User Account: "ops"
Administrators should act swiftly to secure their networks against these vulnerabilities and monitor for indicators of compromise as outlined above.
Join the discussion — sign up to comment, upvote, and save articles.