Network equipment manufacturer MikroTik has announced the release of patches for six critical vulnerabilities found in its RouterOS software. The company strongly advises users to install these updates promptly, as two of the vulnerabilities have been reportedly exploited by attackers.
Exploited Vulnerabilities and Impact
The vulnerabilities, collectively referred to as MikroTrick, allow malicious actors to bypass authentication mechanisms and gain control over affected devices, according to CERT Poland. MikroTik’s advisory highlights the need for immediate patching and directs users to CERT Poland’s detailed guidance for further information.
Although most device configurations are not at risk, MikroTik recommends users block SSH access from untrusted sources. Devices that have been compromised will display a “Flagged” entry in their logs, indicating a security breach.
Details of the Security Flaws
CERT Poland has confirmed that two of the vulnerabilities have been used in tandem to compromise devices. The organization has identified three primary vulnerabilities: CVE-2026-67276, an SSH authentication bypass issue with a CVSS score of 9.2; CVE-2026-86060, related to SSH session privilege manipulation, also scoring 9.2; and CVE-2026-67277, a memory disclosure and denial-of-service flaw with a CVSS score of 8.8.
Attackers have been exploiting these vulnerabilities since early September, creating unauthorized accounts named ‘ops’ and launching attacks from IP addresses 82.192.72.4 and 103.102.31.18. Users are encouraged to investigate any signs of these artifacts on their devices.
Updating to Secure Versions
MikroTik users are urged to upgrade their devices to the latest versions of RouterOS, specifically 7.25beta3, 7.24.2, 7.23.4, or 6.49.21, to mitigate these risks. The updates also address other vulnerabilities, including CVE-2026-67278, which allows TLS server impersonation; CVE-2026-67279, permitting unauthorized file manipulation; and CVE-2026-67281, enabling disclosure of root-owned files.
A recent scan by the Shadowserver Foundation identified over 120,000 MikroTik devices with publicly accessible SSH services, underscoring the urgency of applying these patches.
By taking immediate action, users can protect their devices from potential exploitation and ensure the ongoing security of their network infrastructure.
