Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Chained SSH Vulnerabilities (CVE‑2026‑67279, CVE‑2026‑86060) Enable Password‑less Takeover of MikroTik RouterOS

A state‑machine flaw and an argument‑injection bug in MikroTik RouterOS can be combined to bypass authentication and gain full administrative control of Internet‑exposed routers. The issue highlights the need for robust access‑control evidence and continuous device‑posture monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Chained SSH Vulnerabilities (CVE‑2026‑67279, CVE‑2026‑86060) Enable Password‑less Takeover of MikroTik RouterOS

What It Is – Two independent flaws in MikroTik RouterOS SSH handling can be chained: a state‑machine bug (CVE‑2026‑67279) and an argument‑injection issue in the login routine (CVE‑2026‑86060). Together they let an unauthenticated remote actor obtain full administrative rights on an Internet‑exposed router.

Exploitability – Public proof‑of‑concept exploits have been published and attack logs show successful exploitation in the wild. CVSS scores have not been released yet, but the impact (full control) places the risk in the High range.

Affected Products – MikroTik RouterOS (all versions vulnerable to the two CVEs).

Why It Matters for Trust & Control Assurance

  • Access‑control assurance – The flaw bypasses authentication, exposing a gap in identity verification and privileged‑access controls that auditors will scrutinize.
  • Continuous device‑posture monitoring – Demonstrable evidence that routers are patched and that unauthorized configuration changes are logged is essential for a defensible audit trail.
  • Supply‑chain diligence – Network‑infrastructure vendors must be included in a vendor‑risk program; unpatched routers undermine the organization’s overall trust posture.

Recommended Actions

  • Apply MikroTik’s security patches for CVE‑2026‑67279 and CVE‑2026‑86060 immediately.
  • Inventory all RouterOS devices, prioritize those exposed to the Internet, and enforce “deny‑by‑default” SSH access.
  • Enable centralized logging and integrate router logs into a SIEM for continuous monitoring of authentication attempts.
  • Incorporate router patch status into your third‑party risk dashboard to maintain up‑to‑date evidence for auditors.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →