Recent reports have revealed the presence of 6 vulnerabilities in the RouterOS operating system used in MikroTik routers. Of particular concern is the combination of two vulnerabilities that can potentially allow remote attackers to gain full control over devices with administrator rights, as long as they are accessible via SSH. Incidents of these vulnerabilities being exploited have already been documented.
Mikrotik has released patches to address these vulnerabilities, starting from September 3. The patches include fixes in RouterOS 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21. It is believed that attackers may have been able to discern the nature of the vulnerabilities from studying these patches.
The identified vulnerabilities, namely CVE-2026-67276 and CVE-2026-86060, have been classified as critical with a severity level of 9.2 out of 10. The first vulnerability stems from an issue in the verification of RSA public keys used in SSH authentication. This flaw could allow attackers to generate a fake key and establish an SSH connection without requiring access to the private key. The second vulnerability results from a lack of filtering for invalid characters in SSH usernames.
To detect successful exploitation of these vulnerabilities, users can monitor their RouterOS log for any suspicious activities. It is crucial for MikroTik router users to apply the latest patches provided by the company to mitigate the risks associated with these vulnerabilities.