Tech News
← Home  ·  All topics

Mikrotik Routeros

3 GoKawiil briefs on this topic

CISA adds WSO2, Adobe Commerce, SharePoint flaws to exploited vulnerabilities list

CISA has confirmed active exploitation of four vulnerabilities: a maximum-severity JWT authentication bypass in WSO2 API Manager and related products (CVE-2026-5430), a critical Adobe Commerce flaw (CVE-2026-71362), a high-severity SharePoint code injection bug (CVE-2026-65660), and a medium-severity Mikrotik RouterOS SSH bypass (CVE-2026-67279). Federal agencies must patch or mitigate the two critical flaws by September 27. Security firm watchTowr said its honeypots captured forged-token exploitation attempts against WSO2 systems starting September 13.

MikroTik RouterOS SSH flaws chained in active router hijacking attacks

Attackers are combining two newly disclosed MikroTik RouterOS vulnerabilities, an SSH authentication bypass (CVE-2026-67276) and a privilege escalation bug (CVE-2026-86060), to seize full control of routers with SSH exposed to the internet. Poland's CERT, which found the flaws with AI assistance, calls the combined exploit 'MikroTrick' and confirms it is being used in real-world attacks. MikroTik patched the issues in RouterOS versions released September 3, alongside a related bandwidth-test flaw that can leak memory or crash devices.

Researchers reverse-engineer MikroTik's undisclosed RouterOS 7.23.4 security patch

MikroTik simultaneously released RouterOS 7.23.4, 7.24.2 and 6.49.21 on September 3, 2026, each flagging an unspecified 'important security update' without disclosing details. A security researcher reverse-engineered the binary diffs across versions and identified two exploitable flaws: a low-exponent RSA signature forgery leading to an mtget buffer overflow, and an SSH authentication bug where a username value of -2 grants a read-only session elevated privileges, enabling full command execution on the router.