CRITICAL: MikroTik RouterOS Flaws Chained to Hijack Routers Over SSH
MikroTik patched CVE-2026-67276 and CVE-2026-86060, two CVSS 9.2 RouterOS SSH flaws that CERT Polska found chained in the wild into an unauthenticated full admin takeover dubbed MikroTrick. Exploitation began a day before fixes shipped, CISA added CVE-2026-86060 and CVE-2026-67277 to KEV, and roughly 122,500 devices expose SSH. Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 and audit for rogue accounts.