Hackers exploit new MikroTik RouterOS flaws to hijack routers
What happened
Poland's CERT confirmed active exploitation of the "MikroTrick" chain, which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060) to seize control of internet-exposed MikroTik routers. The agency recommends isolating affected devices, preserving logs, and performing a factory reset, while MikroTik has released patches in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.
Why it ranks #1
Poland's CERT confirmed active exploitation of the "MikroTrick" chain, which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060) to seize control of internet-exposed MikroTik routers.
Who should care
CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- actively exploited