FR
live
tag

#ssh

The MikroTrick chain opens the RouterOS admin console with no password or SSH key

CERT Polska has documented the MikroTrick chain: two RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, combine to hand attackers full administrative control of an exposed router with no password and no SSH key. CISA added CVE-2026-67279 to its KEV catalog on September 25, 2026: patch to 6.49.21, 7.23.4 or 7.24.2 and hunt for signs of compromise.

MikroTik patches routers hijacked over internet-exposed SSH

CERT Polska warns that attackers are taking full administrative control of MikroTik routers whose SSH service is reachable from the internet, without authentication. Update RouterOS and audit the configuration before putting any device back into service.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss