THREAT OPS › Threat News › MikroTik router flaws allow takeover without a password
MikroTik router flaws allow takeover without a password
<p class="wp-block-paragraph"><a href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/" rel="noreferrer noopener nofollow" target="_blank">CERT Polska warns</a> that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.</p>
<p class="wp-block-paragraph">Although the warning com
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-67276cve
- CVE-2026-86060cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/url
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/url
- https://www.cve.org/CVERecord?id=CVE-2026-67276url
- https://www.cve.org/CVERecord?id=CVE-2026-86060url
- https://mikrotik.com/downloadurl
- https://forum.mikrotik.com/t/v7-25beta-development-is-released/272788url