Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

MikroTik RouterOS: 3 Exploited Pre-Auth SSH & btest Bugs (CVE-2026-86060, 67277, 67279)

Critical CVE-2026-86060, CVE-2026-67277, CVE-2026-67279 — Three RouterOS flaws reachable without a password through SSH and the bandwidth-test service are being actively exploited. Upgrade to 7.24.2, 7.23.4 or 6.49.21. How to check and lock down a MikroTik router.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your MikroTik router exposes SSH (port 22) or the bandwidth-test server (TCP/UDP 2000) to the internet, attackers can escalate privileges, read kernel memory, crash it, or write files on it, all without valid credentials. CERT Polska and CISA report active exploitation. Upgrade to RouterOS 7.24.2 (stable), 7.23.4 (long-term) or 6.49.21 (v6 long-term) and close SSH and btest to the WAN.

CVE-2026-86060SSH login: crafted username changes the RouterOS policy mask → privilege escalation. CVSS 4.0: 9.2
CVE-2026-67277btest service: unauthenticated test leaks kernel memory and can reboot the router. CVSS 4.0: 8.8
CVE-2026-67279SSH rekey before login skips authentication → run commands that create/overwrite files. CVSS 4.0: 6.9
AffectedRouterOS 6.x before 6.49.21, 7.x before 7.23.4, 7.24 before 7.24.2
Fixed in6.49.21 (long-term), 7.23.4 (long-term), 7.24.2 (stable)
Exploited?Yes, CISA KEV 2026-09-10 (86060, 67277) and 2026-09-25 (67279)

What the bugs are

All three are reachable before login, which is what makes them dangerous on routers with management services open to the internet:

  • CVE-2026-86060: RouterOS’s SSH login helper mishandles usernames that start with a prohibited character. A crafted username lets an attacker change the trusted policy mask that decides what a session can do, escalating privileges.
  • CVE-2026-67277: the bandwidth-test (btest) server accepts a “related” connection before the primary session has authenticated. An unauthenticated client can then start a UDP test that sends back uninitialised kernel buffer data (a memory leak), and a size-calculation underflow can crash and restart the router.
  • CVE-2026-67279: if an SSH client asks for a rekey before authenticating, RouterOS moves on to the session stage anyway. The attacker can open a channel and send commands that create or overwrite files in RouterOS’s file area, including support files that contain configuration data.

MikroTik shipped the fixes quietly at first; researchers reverse-engineered the 7.23.4 patch, and CERT Polska then reported the bugs being exploited in the wild.

Am I affected?

/system resource print          # look at "version"
/ip service print               # is ssh enabled, and on which address/port?
/tool bandwidth-server print    # is the btest server enabled?

Or in Winbox/WebFig: System → Packages, IP → Services, Tools → BTest Server.

Vulnerable if the version is below 6.49.21 (v6), below 7.23.4 (v7 long-term), or 7.24.x below 7.24.2.

How to patch

/system package update check-for-updates
/system package update install
# after it reboots, also update the bootloader:
/system routerboard upgrade
/system reboot

Take a backup first (/system backup save and /export file=pre-upgrade), and download the files off the router.

Lock it down (do this even after patching)

  • Turn off the btest server unless you use it: /tool bandwidth-server set enabled=no
  • Restrict SSH and Winbox to your LAN or a management subnet: /ip service set ssh address=192.168.88.0/24 (same for winbox, www, api). Disable services you don’t use: /ip service disable telnet,ftp,api,api-ssl,www
  • Make sure the default input-chain firewall drops anything not coming from the LAN: the stock rule drop all not coming from LAN on /ip firewall filter should be present and enabled.
  • Manage the router remotely over WireGuard (built into RouterOS 7) instead of exposing SSH.

Was my router hit?

  • Check /user print for accounts you didn’t create and /system scheduler print / /system script print for unknown entries.
  • Look at /file print for unexpected files, and /log print where topics~"ssh|account" for logins from unknown IPs.
  • Check /ip socks print, /ip proxy print and /ip dns print. Compromised MikroTiks are commonly turned into proxies or have DNS hijacked.
  • If anything is off, netinstall a clean RouterOS, restore config by hand (not from a backup that might be tampered with), and change all passwords.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories