27 SEP 2026 — The patch advice for MikroTik routers has not changed, but the account of the early-September takeover has. CERT Polska, Poland's national computer emergency team, now says the chain pairs CVE-2026-67279 with CVE-2026-86060, and that CVE-2026-67276 was associated with it by mistake.
The updates MikroTik released at the start of September fix both flaws in the corrected chain.
What was reported, and what changed
On 7 September we reported from CERT Polska's first advisory that two chained flaws gave full control of a MikroTik router and and that attacks had begun before the fixes. At that point the pair was CVE-2026-67276 and CVE-2026-86060.
CERT Polska's technical analysis of 22 September revises the first half. By its account, 67276 is a separate vulnerability: it needs knowledge of an account and gives limited access. The flaw that actually lets an attacker skip SSH authentication is 67279. CERT Polska describes it as the server moving on to handle a session after an interrupted login instead of finishing it.
The second half of the chain is unchanged. CVE-2026-86060 lets the attacker give that session full administrative privileges.
Why the patch advice holds
CERT Polska's original advisory of 5 September listed six RouterOS flaws, 67279 among them, with fixed versions for each. The fixes for 67279 and 86060 are the same releases: 7.24.2, 7.23.4 and 6.49.21, or anything later.
A router updated after our first report is covered against the chain as now understood. The correction changes which flaw did the work; the releases an owner needs to install are unchanged.
One entry in the same advisory needs a later release. CVE-2026-67278, which is not part of the chain, is fixed only in 7.24.3 and 7.23.6.
CISA's catalogue followed the correction
The United States cybersecurity agency added 86060, together with CVE-2026-67277, to its Known Exploited Vulnerabilities catalogue on 10 September. It added 67279 on 25 September, in the same alert as a SharePoint flaw, with a federal deadline of 28 September.
67276, the flaw first linked to the chain, does not appear in the catalogue, which matches the corrected account.
Patched is not the same as clean
The attacks began before the fixes existed. CERT Polska dates the earliest public attack logs to 2 September and says patches arrived on 3 September, so a router exposed during that window may already have been entered.
CERT Polska's logs show attackers created a full-privilege account named ops and fetched diagnostic files containing configuration data. The security firm Bishop Fox, which reproduced the takeover on RouterOS 7, found accounts, scripts and scheduled tasks left on compromised devices, including a script that recreated a backdoor account every day.
"Patch status and compromise status are separate questions," Bishop Fox wrote. On version 6, it found the chain bypassed authentication but did not reach administrative control.
What to check on a router
Confirm the release first. Anything at or above 7.24.2, 7.23.4 or 6.49.21 is fixed against this chain.
Then look for signs of a visit. Bishop Fox advises auditing privileged accounts, scripts, scheduled tasks and configuration history, and rotating every secret the router stored or could see. CERT Polska lists an unexpected ops account in the full group, and diagnostic files being created or sent out, among its indicators.
Restrict SSH to trusted addresses. If the internet cannot reach the SSH service, the chain cannot start.