CuraSec

Act active

MikroTrick chain enables unauthenticated MikroTik router takeover

2026-09-24 15:49 UTC · The Hacker News · read the source ↗ #mikrotik#routeros#ssh-exploit
  • Engineer — Act: CVE-2026-86060 is CISA KEV listed with a public PoC, and the chain enables unauthenticated admin takeover of internet-exposed RouterOS devices. Immediately patch RouterOS to the vendor-fixed version, disable SSH exposure on WAN interfaces, and audit firewall rules to confirm MikroTik management ports are not reachable from the internet.
  • SOC/IR — Act: CVE-2026-86060 is KEV listed and attack logs confirm real-world exploitation; hunt for anomalous SSH sessions or new admin accounts on any MikroTik devices in the estate since the earliest known attack date, and add detections for unauthenticated admin-session establishment on edge routers.
  • Leader — Skip
  • Signals: CVE-2026-67279 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub · CVE-2026-86060 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.