RouterOS Ran the Command Before Anyone Logged In — MikroTrick Is Now in KEV
On 25 September 2026 CISA added CVE-2026-67279 — MikroTik RouterOS, improper enforcement of behavioral workflow — to its Known Exploited Vulnerabilities catalog, with a remediation due date of 28 September. CISA's own entry spells out why a CVSS 6.5 information-disclosure-sounding bug earned a three-day clock: it "can be chained to achieve unauthenticated exploitation of CVE-2026-86060." One flaw gets you a command channel without logging in. The other decides what privileges that command runs with. Together, CERT Polska named the chain MikroTrick, and it means full administrative takeover of an internet-facing router by an attacker who never presented a credential.
The state machine, not the crypto
The interesting part of CVE-2026-67279 is that nothing was broken in the authentication logic itself. Per NVD and CERT Polska's advisory, RouterOS's SSH server enters the connection protocol after a client-requested rekey even though user authentication was never attempted. SSH's transport layer allows either side to renegotiate keys mid-connection; RouterOS treated the post-rekey state as though the connection had already progressed past userauth. An unauthenticated client can therefore open a session channel and send an exec request, and affected builds dispatch the command.
What that primitive buys, in CERT Polska's description, is unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace — including support files that carry configuration and diagnostic data. That is already a serious pre-auth foothold. The chain makes it worse: CVE-2026-86060 is an argument-injection flaw (CWE-88) in the SSH login path involving usernames that begin with a prohibited character, which allows the trusted RouterOS policy mask to be altered. CERT Polska rates it CVSS 9.2, and notes that exploiting it "requires an unauthenticated SSH session to reach the RouterOS login helper" — exactly what 67279 provides. The resulting session, in CERT Polska's words, has full administrative privileges.
Six flaws, not two
CERT Polska's advisory page, crediting researcher Sławomir Rozbicki, lists six RouterOS CVEs disclosed on 5 September 2026:
- CVE-2026-67276 (CVSS 9.2) — SSH public-key authentication bypass. RouterOS matched an authorization request against the key type and modulus but omitted the exponent, while verifying the signature using the client-supplied key. An attacker who knows an authorized RSA modulus can present a key with exponent one, forge a valid signature, and log in as that user without ever holding the private key.
- CVE-2026-86060 (CVSS 9.2) — argument injection in the SSH login path; privilege escalation to full admin policy.
- CVE-2026-67279 — the post-rekey state confusion described above. In KEV.
- CVE-2026-67277 (CVSS 8.8) — bandwidth-test service accepts a "related" btest connection before the primary session has authenticated. With
random-data=falsethe sender transmits an uninitialized tail from a kernel packet buffer; a separate inverted size check underflows and can restart the kernel. Memory disclosure or remote DoS, unauthenticated. - CVE-2026-67281 — unauthenticated file read in WebFig's
/jsproxypath via a stale uninitialized principal pointer, combined with parent-directory traversal inside an encrypted URI, disclosing root-owned files including credential stores. - CVE-2026-67278 — acceptance of malformed RSA/PKCS#1 v1.5 signatures across TLS/X.509 validation and SSH host-key authentication. Because RouterOS's trust store includes an e=3 root CA, an attacker who can redirect an outbound RouterOS TLS connection can forge a trusted intermediate from that root's public certificate alone and impersonate arbitrary hostnames.
Three of the six are pre-auth. Two are cryptographic verification failures of the most classic kind. The Bleichenbacher-style e=3 signature forgery in 67278 is a bug class that has been public since 2006 and still shipped in a widely deployed router OS in 2026.
The incomplete fix
The patch matrix is not one row. MikroTik's security bulletin, dated 3 September 2026, lists fixes in 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21. But CERT Polska adds a correction that anyone who patched in early September needs to read: for CVE-2026-67278, "releases 7.23.4 and 7.24.2 included an incomplete fix." The complete fix for the signature-verification flaw arrived only in 7.23.6 (Long-term) and 7.24.3 (Stable), and 67278 affects only the 7.x branch. So a device on 7.24.2 is protected against the exploited chain and still vulnerable to the TLS impersonation issue.
The version boundaries for the KEV'd flaw itself, per NVD: RouterOS 6.0 through before 6.49.21, 7.0 through before 7.23.4, and 7.24 through before 7.24.2.
Exploitation, and MikroTik's unusual response
CERT Polska published a second post confirming it had obtained confirmation that attackers are exploiting this combination of vulnerabilities against RouterOS devices whose SSH service is reachable from public networks, and that the released patches stop the observed attacks. That confirmation, not a theoretical severity score, is what put 67279 in KEV.
Two details in the vendor response are worth recording. First, MikroTik initially published the bulletin without technical detail — "To give time to update your systems, we are not currently publishing detailed information" — and only later named the CVEs and the MikroTrick codename, pointing readers to CERT.pl. Second, CERT Polska notes that alongside the update MikroTik sent a push notification to the phones of users with the MikroTik app installed, for the first time in its history. A router vendor breaking a decades-old communication pattern is a severity signal in its own right.
The patched releases also ship a defensive mechanism: at startup RouterOS scans the configuration for known signs of unauthorized changes, disables recognized suspicious entries, and marks the device "Flagged" in the log. MikroTik's guidance is that a critical log entry saying the device has been Flagged means following its Flagged-status procedure — and that even unflagged devices should be inspected after upgrade for unknown scripts, users, proxies, tunnels, and scheduler tasks.
Why this belongs in an AI-infrastructure feed
The same pattern has run through this site's coverage all month: the boxes that mediate access are the boxes being taken. Two NetScaler RCE zero-days landed in KEV three days later, F5's BIG-IP APM OAuth path took an unauthenticated RCE, and WSO2's gateway layer allowed forged admin tokens. RouterOS is the same category one layer down — and it is the layer that terminates the VPN tunnels your self-hosted model servers, MCP gateways, and agent runners sit behind. A "not internet-facing" inference box is an assertion about a router's configuration, and CVE-2026-67281 hands an unauthenticated attacker the credential stores that configuration is written with.
An attacker with admin on the edge router does not need to attack your agent stack. They can read the tunnel definitions, add their own, and arrive inside the trust boundary that every "internal only" control you built depends on.
What to do
- Upgrade past the incomplete fix, not just to it. 6.49.21 closes the 6.x exposure. On 7.x, 7.23.6 or 7.24.3 — not 7.23.4 / 7.24.2 — is the build that also resolves CVE-2026-67278.
- Get SSH off the internet. MikroTik's default configuration blocks the port from WAN; the exposed devices are ones where someone opened it deliberately. Restrict to trusted source addresses, or front management with WireGuard and expose no management ports at all.
- Check the log for "Flagged" before you trust the device. Patching a compromised router produces a patched compromised router. Review users, scripts, schedulers, proxies, and tunnels against a known-good config.
- Rotate what the router could read. CVE-2026-67281 discloses root-owned configuration stores containing credentials, and 67279 exposes support files with configuration and diagnostic data. Treat every secret that lived in that config — RADIUS keys, VPN pre-shared keys, SNMP communities, tunnel credentials — as disclosed on any device that was reachable.
- Do not rely on outbound TLS from RouterOS until 67278 is fixed. Anything the router fetches or validates over TLS — certificate checks, cloud management, update channels — is impersonable by an attacker positioned on the path.
Sources:
- CERT Polska — “Vulnerabilities in Mikrotik RouterOS software” (5 September 2026; all six CVEs, affected version ranges, incomplete-fix note for CVE-2026-67278)
- CERT Polska — “Critical vulnerabilities in MikroTik RouterOS are being actively exploited” (5 September 2026; MikroTrick chain, confirmed in-the-wild exploitation, Flagged mechanism, push notification)
- MikroTik — “September 2026 vulnerability” security bulletin (3 September 2026; fixed builds 7.25beta3 / 7.24.2 / 7.23.4 / 6.49.21, SSH exposure guidance, Flagged status)
- CISA — Known Exploited Vulnerabilities Catalog entry for CVE-2026-67279 (added 25 September 2026, due 28 September 2026; chaining note to CVE-2026-86060)
- NVD — CVE-2026-67279 (CWE-841; CVSS 3.1 6.5 / CVSS 4.0 6.9; affected version ranges)