Skip to content
Threat Feed
critical threat exploited PoC updated

Active Exploitation of MikroTik RouterOS via SSH

Multiple vulnerabilities in MikroTik RouterOS are being actively exploited in the wild, targeting internet-exposed SSH services to achieve full system compromise.

CVE search metadata

CVE search record: CVE-2026-67276. EPSS: 0.24%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/

CVE search record: CVE-2026-67277. EPSS: 0.43%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/

CVE search record: CVE-2026-86060. EPSS: 0.40%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/

What's new

  • 1. poc_available Sep 9, 12:56 via sploitus
  • 2. added CVE-2026-67276 +2 Sep 8, 22:24 via cccs

The Netherlands National Cyber Security Centre (NCSC) has issued an alert regarding multiple serious vulnerabilities in MikroTik RouterOS that are currently being actively exploited. The threat actor activity specifically targets routers that have SSH services exposed directly to the internet. Successful exploitation of these vulnerabilities allows unauthorized remote attackers to gain full administrative control over the affected network device.

Impacts of a successful compromise include complete network takeover, the ability to intercept or redirect sensitive data traffic, and the potential for total loss of network connectivity. These routers are frequently utilized in enterprise and internet service provider environments, meaning that a compromise could cause widespread service disruption and significant business process failure. MikroTik has released patches in versions 6.49.21, 7.23.4, and 7.24.2 to address the vulnerabilities.

Impact

Successful exploitation results in full administrative control over the router. In enterprise and ISP environments, this grants attackers the ability to intercept organizational data, pivot into internal network segments, or perform denial-of-service attacks by disabling connectivity. Organizations failing to patch are at high risk of total infrastructure compromise.

Recommendation

  • Upgrade MikroTik RouterOS to version 6.49.21, 7.23.4, or 7.24.2 immediately to mitigate the underlying vulnerabilities.
  • Disable direct internet-facing SSH access on all router interfaces.
  • Restrict administrative access to SSH services by implementing VPN-only access or IP-based whitelisting.
  • Audit logs for unauthorized SSH sessions or unexpected configuration changes on all public-facing RouterOS devices.

Immediate actions

Upgrade MikroTik RouterOS to versions 6.49.21, 7.23.4, or 7.24.2.

IT Operations 24h

Mitigations

Remove public SSH access; implement VPN or whitelist.

immediate IT Operations

Publicly accessible SSH services