Active Exploitation of MikroTik RouterOS via SSH
Multiple vulnerabilities in MikroTik RouterOS are being actively exploited in the wild, targeting internet-exposed SSH services to achieve full system compromise.
CVE search metadata
CVE search record: CVE-2026-67276. EPSS: 0.24%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/
CVE search record: CVE-2026-67277. EPSS: 0.43%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/
CVE search record: CVE-2026-86060. EPSS: 0.40%. KEV: no. Product: RouterOS (< 6.49.21, 7.23.4, 7.24.2), RouterOS (< 6.49.21), RouterOS (< 7.23.4), RouterOS (< 7.24.2), RouterOS (< 7.25 beta 3). Brief: Active Exploitation of MikroTik RouterOS via SSH. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotik-routeros-exploitation/
What's new
The Netherlands National Cyber Security Centre (NCSC) has issued an alert regarding multiple serious vulnerabilities in MikroTik RouterOS that are currently being actively exploited. The threat actor activity specifically targets routers that have SSH services exposed directly to the internet. Successful exploitation of these vulnerabilities allows unauthorized remote attackers to gain full administrative control over the affected network device.
Impacts of a successful compromise include complete network takeover, the ability to intercept or redirect sensitive data traffic, and the potential for total loss of network connectivity. These routers are frequently utilized in enterprise and internet service provider environments, meaning that a compromise could cause widespread service disruption and significant business process failure. MikroTik has released patches in versions 6.49.21, 7.23.4, and 7.24.2 to address the vulnerabilities.
Impact
Successful exploitation results in full administrative control over the router. In enterprise and ISP environments, this grants attackers the ability to intercept organizational data, pivot into internal network segments, or perform denial-of-service attacks by disabling connectivity. Organizations failing to patch are at high risk of total infrastructure compromise.
Recommendation
- Upgrade MikroTik RouterOS to version 6.49.21, 7.23.4, or 7.24.2 immediately to mitigate the underlying vulnerabilities.
- Disable direct internet-facing SSH access on all router interfaces.
- Restrict administrative access to SSH services by implementing VPN-only access or IP-based whitelisting.
- Audit logs for unauthorized SSH sessions or unexpected configuration changes on all public-facing RouterOS devices.
Immediate actions
Upgrade MikroTik RouterOS to versions 6.49.21, 7.23.4, or 7.24.2.
Mitigations
Remove public SSH access; implement VPN or whitelist.
Publicly accessible SSH services