Urgent.News

What's breaking now, across thousands of outlets.

Tech

RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060

RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060 Vulnerability overview Most vulnerability write-ups describe mechanism. This one starts from position, because the position is what makes the MikroTrick chain in MikroTik RouterOS worth a management conversation. RouterOS devices commonly sit on the boundary between an organisation and the internet, and the two…

Two critical vulnerabilities, CVE-2026-67279 and CVE-2026-86060, were recently fixed in MikroTik RouterOS devices that operate at the network edge. These flaws allow full administrative control of the affected devices, posing significant operational risk. RouterOS devices are commonly deployed at the internet boundary, making them prime targets for attackers.

The first vulnerability mishandles SSH rekey during authentication, while the second has the login helper read a hyphen-prefixed username as an option without checking a password. Neither step requires a key, making the attack remotely automatable, targeting a management listener, and terminating in full policy control. An impacted device can change routing, create unauthorized paths, maintain access via VPN/IPsec keys, and create a persistence mechanism that survives reboots and updates.

Public logs show a privileged ops account created through SSH and a device diagnostic file exported externally. The September 2026 updates cover RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Devices that were internet-facing before the date require a post-patch review. As of the ZoomEye measurement, 9,559 devices are potentially vulnerable.

To mitigate the risk, router updates should be treated as scheduling-critical, and public management reachability should be eliminated where possible. Accounts should be audited and flagged post-patching, and SSH logs should be reviewed for hyphen-prefixed usernames during the exposure window. All secrets stored on affected devices should be rotated, and routing and firewall configurations should be re-baselined.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Building The Apex Calc: A Fast, Ad-Free Financial & Amortization Utility

Most online financial calculators are buried under invasive display ads, auto-playing video popups, and slow third-party analytics trackers.

  • The Apex Calc is ad-free and privacy-first financial utility.
  • Features include mortgage calculations, wage conversion, and compound interest modeling.
  • Operates entirely in the browser with no server requests or data collection.

More from Sunday 27 September →