CiberLATAMbywhalemate

Ecuador warns of active MikroTik RouterOS flaws

ECUCERT flagged three exploited CVEs in MikroTik RouterOS. Taiwan's NICS-TW and the Dutch DIVD also reported active attacks.

Whalemate Labs · AI-assisted researchPublished:3 min read

Ecuador's CSIRT issued alert AL-2026-046 over critical MikroTik RouterOS flaws under active exploitation, tracked as CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. The warning comes alongside alerts from Taiwan and the Netherlands, which also describe active exploitation and router takeovers on systems exposed to the internet.

Ecuador's CSIRT issued alert AL-2026-046 over critical MikroTik RouterOS vulnerabilities that are being actively exploited, tracked as CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. At the same time, Taiwan's security center and the Dutch CSIRT DIVD also reported high risk, active exploitation, and a chain that can let attackers take over routers exposed to the internet.

What did the response teams say?

ECUCERT said all three flaws are being actively exploited. NICS-TW, Taiwan's National Cyber Security Center, focused its alert on CVE-2026-67276 and CVE-2026-86060, and said the latter is already under active exploitation. DIVD, meanwhile, published case DIVD-2026-00012 on the MikroTrick chain and linked it to the takeover of MikroTik RouterOS devices exposed to the internet.

Which RouterOS versions are affected?

According to NICS-TW, the vulnerable range includes RouterOS 7.24 through versions before 7.24.2, 7.0.0 through versions before 7.23.4, and 6.0.0 through versions before 6.49.21. HawkEye also said MikroTik patched these flaws in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21, the first publicly associated fixed versions tied to the MikroTrick chain.

How does the MikroTrick chain work?

The technical advisories agree that exploitation combines an SSH authentication bypass with a bug in the login process. HawkEye described CVE-2026-67276 as an incorrect RSA public key validation issue that allows SSH authentication to be bypassed, while CVE-2026-86060 manipulates SSH session privileges through specially crafted usernames. According to the same bulletin, chaining 67276 and 86060 allows administrative access without authentication.

What technical impact is attributed to each CVE?

HawkEye assigned CVE-2026-67276 a CVSS v4 score of 9.2 and gave CVE-2026-86060 the same 9.2 rating. It also described CVE-2026-67277 as an information disclosure and denial-of-service issue in the bandwidth test service, with a CVSS score of 8.8. EveryWAN and Kaspersky agreed that 67276 involves an SSH authentication bypass, while 86060 enables privilege escalation using usernames with invalid characters.

What is the potential scale of the problem?

Infosec.ge estimated that about 122,500 MikroTik routers are exposed with vulnerable RouterOS instances tied to the MikroTrick chain, broadening the potential impact on a global scale. In the same material, different analyses cited by Mallory, Aviatrix Threat Research, CERT Polska and Bishop Fox show public confusion over the exact CVE identifier for the SSH state-machine flaw, which in some advisories appears as CVE-2026-67279 and in others as CVE-2026-67276 or CVE-2026-67277.

What confusion appears in the technical advisories?

Several independent analyses described the chain as a combination of an SSH state-machine flaw and CVE-2026-86060 in RouterOS login, but not all used the same identifier for that component. Mallory and Aviatrix Threat Research noted that naming difference, while CyberExperts and Cyberinfos cited CERT Polska and Bishop Fox to argue that both CVEs are already being exploited on the internet and leave traces of hidden persistence accounts on compromised routers.

Sources

View all