
CISA Puts MikroTik RouterOS SSH Workflow Flaw CVE-2026-67279 on KEV
Federal agencies have until September 28 to remediate internet-exposed RouterOS devices after CISA confirmed active exploitation of the SSH state-machine bug used in the MikroTrick takeover chain.
Noah Park, ResponseNew York4 min read
WASHINGTON - The Cybersecurity and Infrastructure Security Agency on September 25, 2026, added CVE-2026-67279, an improper enforcement of behavioral workflow flaw in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog, giving Federal Civilian Executive Branch agencies until September 28, 2026, to remediate under Binding Operational Directive 26-04.
CISA's catalog entry says RouterOS can let an unauthenticated client open a session channel and send an exec request, and that the bug can be chained to achieve unauthenticated exploitation of CVE-2026-86060. The KEV row for CVE-2026-67279 lists known ransomware campaign use as Unknown and forensic triage as No. CISA had already listed the companion privilege-escalation bug, CVE-2026-86060, on September 10, 2026. A same-day CISA alert named both CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS as the two new catalog additions.


CERT Polska published a technical analysis on September 22, 2026, naming the chain MikroTrick. According to that write-up, vulnerable RouterOS SSH handling of a client-initiated rekey during authentication moved the server into channel handling without ever sending SSH_MSG_USERAUTH_SUCCESS. CVE-2026-86060 then abused argument handling in /nova/bin/login so a username beginning with a hyphen, commonly -2, could alter the trusted policy mask and yield a full administrative console without a password or SSH key. MikroTik shipped fixed builds on September 3, 2026, in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable), and later documented the issue on its September 2026 vulnerability page. CERT Polska said the earliest publicly posted attack logs dated from September 2, before those patches were available, and that public reports included failed logins for user -2, creation of a privileged ops account, and in some cases transfer of a diagnostic file to an external address.
Bishop Fox researcher Emilio Gallegos, quoted by The Hacker News on September 26, 2026, said the team reproduced full administrative takeover on vulnerable RouterOS 7.x builds and described MikroTrick as combining failures at different trust boundaries. MikroTik advises operators to keep SSH off untrusted networks, to treat a Flagged device status and related log entries as compromise signals, and to inspect users, scripts, and other configuration for unrecognized changes even when Flagged status is not set.


For security operations teams, this is an edge-device control-plane incident, not only a firmware ticket. Priority work is inventory of internet-reachable RouterOS SSH endpoints still below 6.49.21, 7.23.4, or 7.24.2; urgent upgrade or temporary restriction of SSH to trusted management paths; hunting for authentication failures involving usernames that begin with a hyphen, especially -2; review for unexpected fully privileged accounts such as ops; and inspection of schedulers, scripts, tunnels, and recent diagnostic exports. Even though the KEV row for CVE-2026-67279 marks forensic triage No, operators who find those indicators should treat the device as compromised, rotate credentials and keys, and escalate to incident response rather than closing the ticket on patch status alone.
Sources:
Noah Park covers incident response, forensic triage, and containment for SOCtember from New York.
Related stories
Response
Check Point VPN Flaw Is a Remote-Access Control-Plane Incident, Not Only a Gateway Patch
Response
CISA Adds Adobe Commerce Magento Auth Flaw CVE-2026-71362 to KEV
Response
F5 Warns of Exploited BIG-IP APM Flaw Enabling Unauthenticated Remote Code Execution
Response