Back to advisories

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik router exposed to the internet is at immediate risk of compromise.

CRITICALAdvisorySep 07, 2026
Action required
Identify all MikroTik RouterOS instances in your environment. Patch to the latest fixed version immediately. If patching is delayed, restrict SSH access to trusted IPs only and monitor for exploitation attempts against ports 22, 8291, and bandwidth-test services.
Affected products
RouterOSMikroTik