MikroTik Router Vulnerabilities Allowed Admin Access
A chained flaw in RouterOS exposed administrative privileges to remote attackers before patches shipped.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security of the internet-connected devices in your home?
Security researchers identified a vulnerability chain in MikroTik RouterOS that enabled unauthenticated administrative access beginning September 2, 2026. This chain utilized two distinct flaws to bypass authentication and manipulate the login process.
Why it matters
The vulnerability occurred because RouterOS failed to properly sanitize usernames before processing them as command-line arguments, creating a critical security gap. This necessitated urgent patching to prevent unauthorized full administrative access to affected devices.
The exploit chain includes CVE-2026-67279, an SSH state-machine flaw, and CVE-2026-86060, an argument-injection vulnerability. MikroTik released security updates in RouterOS versions 6.49.21, 7.23.4, and 7.24.2 to resolve these issues.
The players
MikroTik
A networking equipment manufacturer specializing in RouterOS and hardware for global internet infrastructure.
CISA
The Cybersecurity and Infrastructure Security Agency that monitors and catalogs threats to critical networks.
CERT Polska
A national computer emergency response team focused on identifying security threats and coordinating incident response in Poland.
The details
The attack mechanism involves initiating an SSH key renegotiation to skip identity confirmation. Once past this check, the attacker provides the username -2, which the login program incorrectly interprets as a command-line instruction. This causes the system to read privilege levels from the terminal instead of validating user credentials, effectively granting full administrative access.
Timeline
September 2, 2026: Attack logs first revealed exploitation of the MikroTrick chain.
September 3, 2026: MikroTik released patched versions of the RouterOS software.
September 5, 2026: CERT Polska issued a public warning regarding the RouterOS flaws.
September 10, 2026: CISA added CVE-2026-86060 to its catalog of known exploited vulnerabilities.
The Tech Race
The addition of this vulnerability to CISA's Known Exploited Vulnerabilities catalog follows an established procedure for tracking high-risk software flaws. It marks a continued effort by authorities to force prompt patching in critical networking hardware against coordinated exploit chains.
Users of MikroTik routers should verify that their systems are running versions 6.49.21, 7.23.4, or 7.24.2 immediately to mitigate the risk of unauthorized access. Failure to update leaves devices susceptible to administrative takeover if exposed to the internet.
The takeaway
This exploit highlights the necessity of strictly isolating user input from command-line arguments in network management software. Administrators should continue to monitor CISA security alerts to identify and patch similar vulnerabilities before they are weaponized.
Further reading
For more on the latest threats to networking hardware, visit the Cybersecurity section.
Live Poll
Do you trust the security of the internet-connected devices in your home?






