Skip to finding
§
High
Edge — Routers
Confirmed
CVE-2026-67276

Attackers are chaining RouterOS SSH flaws to obtain full administrator control without credentials.

An exposed SSH listener is the only required access condition.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and network appliances

What it enables

Unauthenticated full administrative control of internet-exposed RouterOS devices

Reach the router’s SSH service from a public network→↓Exploit incomplete RSA-key comparison to obtain an SSH session without the corresponding private key→↓Use the crafted -2-style username path to alter the session policy mask→↓Gain full RouterOS administrative privileges→↓Observed operators create a highly privileged ops account and can add scripts, proxies and tunnels
Why this matters

CERT Polska confirmed takeovers of publicly reachable devices, turning two authentication defects into an observed credentialless administrator path.

Detail and 5 sources
Required access

Internet reachability to an affected RouterOS SSH service

Affected versions

RouterOS 6.0.0 before 6.49.21, RouterOS 7.0.0 before 7.23.4, RouterOS 7.24 before 7.24.2, RouterOS 6.0.0 through 6.49.20, RouterOS 7.0.0 through 7.23.3, RouterOS 7.24 through 7.24.1

Proof of concept

Demonstrated by the researcher

Incomplete RSA-key comparison opens a session without the authorized private key; crafted username handling then changes the RouterOS policy mask to full administrator privileges. Observed operators created a privileged ops account and could add scripts, proxies and tunnels.

MikroTik fixed every maintained release channel and added boot-time compromise flagging. Pre-fix images remain accepted, so the fix does not prevent a device from returning to a vulnerable build.

Evidence
CERT Polska validated each hypothesis on real RouterOS systems with clean-state repetition and negative controlsCERT Polska confirms successful in-the-wild takeovers using the two-flaw MikroTrick chain against publicly reachable SSH servicesMikroTik shipped fixes in every release channel and added compromise flagging during boot
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026