MikroTik Router Vulnerabilities Allowed Admin Access

A chained flaw in RouterOS exposed administrative privileges to remote attackers before patches shipped.

Updated on Sept. 23, 2026 in Cybersecurity

Isometric editorial illustration of a metallic server rack unit with network cabling, representing network infrastructure and security.
Security researchers identified a vulnerability chain in MikroTik's RouterOS that permitted unauthenticated remote attackers to gain full administrative access to affected devices. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of the internet-connected devices in your home?

Security researchers identified a vulnerability chain in MikroTik RouterOS that enabled unauthenticated administrative access beginning September 2, 2026. This chain utilized two distinct flaws to bypass authentication and manipulate the login process.

Why it matters

The vulnerability occurred because RouterOS failed to properly sanitize usernames before processing them as command-line arguments, creating a critical security gap. This necessitated urgent patching to prevent unauthorized full administrative access to affected devices.

The exploit chain includes CVE-2026-67279, an SSH state-machine flaw, and CVE-2026-86060, an argument-injection vulnerability. MikroTik released security updates in RouterOS versions 6.49.21, 7.23.4, and 7.24.2 to resolve these issues.

The players

MikroTik

A networking equipment manufacturer specializing in RouterOS and hardware for global internet infrastructure.

CISA

The Cybersecurity and Infrastructure Security Agency that monitors and catalogs threats to critical networks.

CERT Polska

A national computer emergency response team focused on identifying security threats and coordinating incident response in Poland.

The details

The attack mechanism involves initiating an SSH key renegotiation to skip identity confirmation. Once past this check, the attacker provides the username -2, which the login program incorrectly interprets as a command-line instruction. This causes the system to read privilege levels from the terminal instead of validating user credentials, effectively granting full administrative access.

Timeline

  1. September 2, 2026: Attack logs first revealed exploitation of the MikroTrick chain.

  2. September 3, 2026: MikroTik released patched versions of the RouterOS software.

  3. September 5, 2026: CERT Polska issued a public warning regarding the RouterOS flaws.

  4. September 10, 2026: CISA added CVE-2026-86060 to its catalog of known exploited vulnerabilities.

The Tech Race

The addition of this vulnerability to CISA's Known Exploited Vulnerabilities catalog follows an established procedure for tracking high-risk software flaws. It marks a continued effort by authorities to force prompt patching in critical networking hardware against coordinated exploit chains.

Users of MikroTik routers should verify that their systems are running versions 6.49.21, 7.23.4, or 7.24.2 immediately to mitigate the risk of unauthorized access. Failure to update leaves devices susceptible to administrative takeover if exposed to the internet.

The takeaway

This exploit highlights the necessity of strictly isolating user input from command-line arguments in network management software. Administrators should continue to monitor CISA security alerts to identify and patch similar vulnerabilities before they are weaponized.

Further reading

For more on the latest threats to networking hardware, visit the Cybersecurity section.

Live Poll

Do you trust the security of the internet-connected devices in your home?