Critical CVE-2026-86060, CVE-2026-67277, CVE-2026-67279 — Three RouterOS flaws reachable without a password through SSH and the bandwidth-test service are being actively exploited. Upgrade to 7.24.2, 7.23.4 or 6.49.21. How to check and lock down a MikroTik router.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your MikroTik router exposes SSH (port 22) or the bandwidth-test server (TCP/UDP 2000) to the internet, attackers can escalate privileges, read kernel memory, crash it, or write files on it, all without valid credentials. CERT Polska and CISA report active exploitation. Upgrade to RouterOS 7.24.2 (stable), 7.23.4 (long-term) or 6.49.21 (v6 long-term) and close SSH and btest to the WAN.
| CVE-2026-86060 | SSH login: crafted username changes the RouterOS policy mask → privilege escalation. CVSS 4.0: 9.2 |
|---|---|
| CVE-2026-67277 | btest service: unauthenticated test leaks kernel memory and can reboot the router. CVSS 4.0: 8.8 |
| CVE-2026-67279 | SSH rekey before login skips authentication → run commands that create/overwrite files. CVSS 4.0: 6.9 |
| Affected | RouterOS 6.x before 6.49.21, 7.x before 7.23.4, 7.24 before 7.24.2 |
| Fixed in | 6.49.21 (long-term), 7.23.4 (long-term), 7.24.2 (stable) |
| Exploited? | Yes, CISA KEV 2026-09-10 (86060, 67277) and 2026-09-25 (67279) |
All three are reachable before login, which is what makes them dangerous on routers with management services open to the internet:
MikroTik shipped the fixes quietly at first; researchers reverse-engineered the 7.23.4 patch, and CERT Polska then reported the bugs being exploited in the wild.
/system resource print # look at "version"
/ip service print # is ssh enabled, and on which address/port?
/tool bandwidth-server print # is the btest server enabled?
Or in Winbox/WebFig: System → Packages, IP → Services, Tools → BTest Server.
Vulnerable if the version is below 6.49.21 (v6), below 7.23.4 (v7 long-term), or 7.24.x below 7.24.2.
/system package update check-for-updates
/system package update install
# after it reboots, also update the bootloader:
/system routerboard upgrade
/system reboot
Take a backup first (/system backup save and /export file=pre-upgrade), and download the files off the router.
/tool bandwidth-server set enabled=no/ip service set ssh address=192.168.88.0/24 (same for winbox, www, api). Disable services you don’t use: /ip service disable telnet,ftp,api,api-ssl,wwwdrop all not coming from LAN on /ip firewall filter should be present and enabled./user print for accounts you didn’t create and /system scheduler print / /system script print for unknown entries./file print for unexpected files, and /log print where topics~"ssh|account" for logins from unknown IPs./ip socks print, /ip proxy print and /ip dns print. Compromised MikroTiks are commonly turned into proxies or have DNS hijacked.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.