MikroTik RouterOS Flaws Exposed Administrative Access
Researchers identified a vulnerability chain that previously allowed attackers to gain full control of affected routers.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security of the internet-connected devices in your home?
Security researchers discovered a vulnerability chain in MikroTik RouterOS that granted unauthenticated users full administrative privileges. The exploit, active as of September 2, 2026, allowed attackers to bypass authentication and manipulate the login process.
Why it matters
The flaws allowed unauthorized actors to create administrative accounts by injecting specific arguments during the login sequence. This vulnerability exposed exposed internet-connected infrastructure to potential takeover before patches were deployed.
The vulnerability chain consists of CVE-2026-67279, an SSH state-machine flaw, and CVE-2026-86060, an argument-injection bug. Attackers used the username -2 to force the system to read privilege levels from the terminal.
The players
MikroTik
This Latvian networking equipment manufacturer produces the RouterOS software used in routers globally.
CISA
The Cybersecurity and Infrastructure Security Agency is a United States federal agency that identifies and coordinates the response to national security threats.
CERT Polska
This is the primary national computer emergency response team in Poland responsible for investigating security incidents.
The details
Attackers initiated an SSH key renegotiation to skip identity checks before inputting the -2 username to trigger the injection flaw. This caused the router to process the input as a command-line argument rather than a legitimate user identity, granting unauthorized access.
Timeline
September 2, 2026: Attack logs confirmed exploitation of the vulnerability chain.
September 3, 2026: MikroTik released patched firmware versions 6.49.21, 7.23.4, and 7.24.2.
September 5, 2026: CERT Polska issued a public warning regarding the RouterOS vulnerabilities.
September 10, 2026: CISA officially added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog.
The Tech Race
This incident highlights the ongoing struggle to secure edge-network hardware against complex exploit chains. The rapid identification and patching of these vulnerabilities underscore the necessity for frequent firmware updates to maintain security against evolving bypass techniques.
Network administrators must ensure their MikroTik devices are updated to versions 6.49.21, 7.23.4, or 7.24.2 to eliminate the authentication bypass risk. Those who fail to update their firmware remain at risk of unauthorized administrative access to their hardware.
The takeaway
Maintaining updated firmware is the primary defense against sophisticated credential bypass attacks on networking equipment. Administrators should proactively audit logs for suspicious IP addresses to ensure their network environment has not been previously compromised.
Further reading
For more information on current digital threats, visit the Cybersecurity section.
Live Poll
Do you trust the security of the internet-connected devices in your home?







