Chained SSH Vulnerabilities (CVE‑2026‑67279, CVE‑2026‑86060) Enable Password‑less Takeover of MikroTik RouterOS
What It Is – Two independent flaws in MikroTik RouterOS SSH handling can be chained: a state‑machine bug (CVE‑2026‑67279) and an argument‑injection issue in the login routine (CVE‑2026‑86060). Together they let an unauthenticated remote actor obtain full administrative rights on an Internet‑exposed router.
Exploitability – Public proof‑of‑concept exploits have been published and attack logs show successful exploitation in the wild. CVSS scores have not been released yet, but the impact (full control) places the risk in the High range.
Affected Products – MikroTik RouterOS (all versions vulnerable to the two CVEs).
Why It Matters for Trust & Control Assurance
- Access‑control assurance – The flaw bypasses authentication, exposing a gap in identity verification and privileged‑access controls that auditors will scrutinize.
- Continuous device‑posture monitoring – Demonstrable evidence that routers are patched and that unauthorized configuration changes are logged is essential for a defensible audit trail.
- Supply‑chain diligence – Network‑infrastructure vendors must be included in a vendor‑risk program; unpatched routers undermine the organization’s overall trust posture.
Recommended Actions
- Apply MikroTik’s security patches for CVE‑2026‑67279 and CVE‑2026‑86060 immediately.
- Inventory all RouterOS devices, prioritize those exposed to the Internet, and enforce “deny‑by‑default” SSH access.
- Enable centralized logging and integrate router logs into a SIEM for continuous monitoring of authentication attempts.
- Incorporate router patch status into your third‑party risk dashboard to maintain up‑to‑date evidence for auditors.
Source: The Hacker News