Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

MikroTik RB951Ui-2HnD router with Ethernet cables connected.
Photo: Deavmi. MikroTik RB951Ui-2HnD. CC BY-SA 3.0 Wikimedia.

Response

CISA Puts MikroTik RouterOS SSH Workflow Flaw CVE-2026-67279 on KEV

Federal agencies have until September 28 to remediate internet-exposed RouterOS devices after CISA confirmed active exploitation of the SSH state-machine bug used in the MikroTrick takeover chain.

Noah Park, ResponseNew York4 min read

WASHINGTON - The Cybersecurity and Infrastructure Security Agency on September 25, 2026, added CVE-2026-67279, an improper enforcement of behavioral workflow flaw in MikroTik RouterOS, to its Known Exploited Vulnerabilities catalog, giving Federal Civilian Executive Branch agencies until September 28, 2026, to remediate under Binding Operational Directive 26-04.

CISA's catalog entry says RouterOS can let an unauthenticated client open a session channel and send an exec request, and that the bug can be chained to achieve unauthenticated exploitation of CVE-2026-86060. The KEV row for CVE-2026-67279 lists known ransomware campaign use as Unknown and forensic triage as No. CISA had already listed the companion privilege-escalation bug, CVE-2026-86060, on September 10, 2026. A same-day CISA alert named both CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS as the two new catalog additions.

CISA graphic titled The Nation's Risk Managers.
Cybersecurity and Infrastructure Security AgencyCISA graphic, The Nation's Risk Managers.
MikroTik hAP ac2 router in front of a RouterBOARD box.
Photo: Uhernandez. MikroTik hAP ac2. CC BY 3.0 Wikimedia.A MikroTik hAP ac2, which runs RouterOS.

CERT Polska published a technical analysis on September 22, 2026, naming the chain MikroTrick. According to that write-up, vulnerable RouterOS SSH handling of a client-initiated rekey during authentication moved the server into channel handling without ever sending SSH_MSG_USERAUTH_SUCCESS. CVE-2026-86060 then abused argument handling in /nova/bin/login so a username beginning with a hyphen, commonly -2, could alter the trusted policy mask and yield a full administrative console without a password or SSH key. MikroTik shipped fixed builds on September 3, 2026, in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable), and later documented the issue on its September 2026 vulnerability page. CERT Polska said the earliest publicly posted attack logs dated from September 2, before those patches were available, and that public reports included failed logins for user -2, creation of a privileged ops account, and in some cases transfer of a diagnostic file to an external address.

Bishop Fox researcher Emilio Gallegos, quoted by The Hacker News on September 26, 2026, said the team reproduced full administrative takeover on vulnerable RouterOS 7.x builds and described MikroTrick as combining failures at different trust boundaries. MikroTik advises operators to keep SSH off untrusted networks, to treat a Flagged device status and related log entries as compromise signals, and to inspect users, scripts, and other configuration for unrecognized changes even when Flagged status is not set.

Close view of a MikroTik RouterBOARD 951Ui-2HnD with a connected Ethernet cable.
Photo: Deavmi. MikroTik wireless router. CC BY-SA 3.0 Wikimedia.Ethernet and power connected on a MikroTik RouterBOARD.
Diagram of the MikroTrick SSH workflow for CVE-2026-67279 and CVE-2026-86060.
Chart: CERT Polska. MikroTrick SSH state diagram.The rekey path into an unauthenticated session, then the login step.

For security operations teams, this is an edge-device control-plane incident, not only a firmware ticket. Priority work is inventory of internet-reachable RouterOS SSH endpoints still below 6.49.21, 7.23.4, or 7.24.2; urgent upgrade or temporary restriction of SSH to trusted management paths; hunting for authentication failures involving usernames that begin with a hyphen, especially -2; review for unexpected fully privileged accounts such as ops; and inspection of schedulers, scripts, tunnels, and recent diagnostic exports. Even though the KEV row for CVE-2026-67279 marks forensic triage No, operators who find those indicators should treat the device as compromised, rotate credentials and keys, and escalate to incident response rather than closing the ticket on patch status alone.

Sources:


Noah Park covers incident response, forensic triage, and containment for SOCtember from New York.

Related stories

Response desk