Attackers are combining two newly disclosed MikroTik RouterOS vulnerabilities, an SSH authentication bypass (CVE-2026-67276) and a privilege escalation bug (CVE-2026-86060), to seize full control of routers with SSH exposed to the internet. Poland's CERT, which found the flaws with AI assistance, calls the combined exploit 'MikroTrick' and confirms it is being used in real-world attacks. MikroTik patched the issues in RouterOS versions released September 3, alongside a related bandwidth-test flaw that can leak memory or crash devices.
bleepingcomputer.com
· 2026-09-07
MikroTik simultaneously released RouterOS 7.23.4, 7.24.2 and 6.49.21 on September 3, 2026, each flagging an unspecified 'important security update' without disclosing details. A security researcher reverse-engineered the binary diffs across versions and identified two exploitable flaws: a low-exponent RSA signature forgery leading to an mtget buffer overflow, and an SSH authentication bug where a username value of -2 grants a read-only session elevated privileges, enabling full command execution on the router.
npratley.net
· 2026-09-05
MikroTik has released the CRS804-4DDQ-hRM, a compact desktop switch offering four QSFP56-DD ports for a combined 1.6Tbps of 400GbE bandwidth. It carries a $1,295 list price but typically sells for around $1,100, and the reviewer has been running it in RDMA backends for NVIDIA GB10 and GB300 clusters for months.
servethehome.com
· 2026-09-03