Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

MikroTik Vulnerability "September 2026"

Hi all!

For those here who use MikroTik, there is a critical vulnerability... "somewhere". MikroTik doesn't provide any details on https://mikrotik.com/supportsec/september-2026-vulnerability/, nor a CVE from what I could gather, so I propose to call it "fuck" in honors of @rpqu :)

Anyway, if you have MikroTiks, you might want to upgrade...

Comments

  • @angstrom Could you move this to the new "Security" category?

  • was mikrotik vm affected? they didn't provide any fucking information :|

  • @glueckself said: MikroTik doesn't provide any details

    The reason: To give time to update your systems, we are not currently publishing detailed information.

  • given what they link to, you know its really really bad. lol

  • olokeoloke Member, Host Rep

    More details:
    https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/

    CVE-2026-67276 - SSH authentication bypass (CVSS: 9.2)
    RouterOS did not properly verify public keys used for SSH authentication - in particular, it did not compare the entire RSA public key assigned to a user. An attacker who knew the username and the public modulus of the user's key could craft a different key and log in via SSH without possessing the corresponding private key. The privileges obtained were equivalent to those of the targeted account.

    CVE-2026-86060 - SSH session privilege manipulation via a crafted username (CVSS: 9.2)
    RouterOS did not properly handle usernames beginning with a disallowed character in the SSH login mechanism. By using a crafted username, an attacker could elevate their privileges. The resulting session had full administrative privileges in the RouterOS system.

    CVE-2026-67277 - memory disclosure and crash via bandwidth-test (CVSS: 8.8)
    The bandwidth-test service allowed an unauthenticated connection to enter a state that should only be reachable after logging in. Combined with two separate flaws - disclosure of uninitialized data from the packet buffer and an integer underflow in size validation - this enabled kernel memory leakage or a remote DoS attack leading to a system restart.

    More CVEs:
    https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/

  • ...so maybe it's a blessing that my RB5009 has been running a broken OpenWRT instance for months after all...
    (Thanks for the heads up; I was considering trying RouterOS again but now I'm 100% just gonna reinstall OpenWRT)

  • olokeoloke Member, Host Rep

    @zejjnt said:
    ...so maybe it's a blessing that my RB5009 has been running a broken OpenWRT instance for months after all...
    (Thanks for the heads up; I was considering trying RouterOS again but now I'm 100% just gonna reinstall OpenWRT)

    OpenWrt is love, although I believe MikroTik is still far more popular especially in corporate environments.

Sign In or Register to comment.