{
  "id": 10181914,
  "title": "RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060",
  "url": "https://urgent.news/2026/09/27/routeros-at-the-network-edge-operational-risk-from-cve-2026-67279-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-27T09:00:16.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/routeros-at-the-network-edge-operational-risk-from-cve-2026-67279-and-cve-2026-86060-2am6"
  },
  "original_language": "en",
  "account": "Two critical vulnerabilities, CVE-2026-67279 and CVE-2026-86060, were recently fixed in MikroTik RouterOS devices that operate at the network edge. These flaws allow full administrative control of the affected devices, posing significant operational risk. RouterOS devices are commonly deployed at the internet boundary, making them prime targets for attackers. The first vulnerability mishandles SSH rekey during authentication, while the second has the login helper read a hyphen-prefixed username as an option without checking a password. Neither step requires a key, making the attack remotely automatable, targeting a management listener, and terminating in full policy control. An impacted device can change routing, create unauthorized paths, maintain access via VPN/IPsec keys, and create a persistence mechanism that survives reboots and updates. Public logs show a privileged ops account created through SSH and a device diagnostic file exported externally. The September 2026 updates cover RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Devices that were internet-facing before the date require a post-patch review. As of the ZoomEye measurement, 9,559 devices are potentially vulnerable. To mitigate the risk, router updates should be treated as scheduling-critical, and public management reachability should be eliminated where possible. Accounts should be audited and flagged post-patching, and SSH logs should be reviewed for hyphen-prefixed usernames during the exposure window. All secrets stored on affected devices should be rotated, and routing and firewall configurations should be re-baselined.",
  "summary": "RouterOS at the Network Edge: Operational Risk From CVE-2026-67279 and CVE-2026-86060 Vulnerability overview Most vulnerability write-ups describe mechanism. This one starts from position, because the position is what makes the MikroTrick chain in MikroTik RouterOS worth a management conversation. RouterOS devices commonly sit on the boundary between an organisation and the internet, and the two…",
  "key_points": [
    "Two critical vulnerabilities CVE-2026-67279 and CVE-2026-86060 fixed in MikroTik RouterOS.",
    "Vulnerabilities allow full administrative control of affected network edge devices.",
    "RouterOS devices at internet boundary, 9,559 potentially vulnerable as of September 2026."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}