Affected Systems

MikroTik RouterOS versions 6.0.0 to 6.49.20, 7.0.0 to 7.23.3, and 7.24 to 7.24.1. All six CVEs affect the same version ranges. Impacts SSH authentication, TLS validation, WebFig interface, and bandwidth test functionality.

Exploitation Status

No active exploitation reported. Vulnerabilities disclosed by CERT Polska through coordinated disclosure. Technical details published, increasing likelihood of PoC development and exploitation attempts.

Business Impact

MikroTik routers are widely deployed in enterprise edge networks, ISPs, and critical infrastructure. These vulnerabilities allow unauthenticated attackers to bypass SSH authentication (CVE-2026-67276, CVE-2026-67279), execute commands without authentication (CVE-2026-67279), read sensitive configuration files including credentials (CVE-2026-67281), escalate privileges (CVE-2026-86060), cause denial of service (CVE-2026-67277), and perform TLS man-in-the-middle attacks (CVE-2026-67278). Combined, these flaws enable full device compromise from the network without credentials. Exposed management interfaces are at immediate risk.

Urgency

đź”´ Immediate

Recommended Actions

  • Immediately upgrade all MikroTik RouterOS devices to patched versions: 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable)
  • Restrict SSH and WebFig management access to trusted IP ranges only; remove exposure from public internet if present
  • Audit RouterOS device logs for suspicious SSH authentication attempts, unexpected session activity, or WebFig /jsproxy requests from unauthenticated sources
  • Inventory all MikroTik devices using network scanning or asset management tools to ensure complete patch coverage
  • Review and rotate credentials stored in RouterOS configuration files, assuming potential compromise if devices were internet-exposed prior to patching

---

# Geopolitical Context

Geopolitical Context

The disclosure by Poland's national CERT of multiple critical vulnerabilities in MikroTik RouterOS—a widely deployed routing platform in both enterprise and critical infrastructure environments—represents a significant contribution to global cybersecurity resilience. MikroTik devices, manufactured by a Latvian company, are extensively used across Europe, Central Asia, and developing markets due to their cost-effectiveness, making them attractive targets for state-sponsored and criminal threat actors. The vulnerabilities span authentication bypass, cryptographic verification failures, and privilege escalation—classes of flaws historically exploited by advanced persistent threat (APT) groups for initial access and lateral movement in network environments. Poland's proactive vulnerability research and coordinated disclosure aligns with broader European Union efforts to strengthen cyber defense capabilities and reduce systemic risk in telecommunications infrastructure, particularly as NATO's eastern flank faces sustained cyber pressure. The timing and scope of this research may reflect heightened awareness within Polish security institutions of the strategic importance of securing edge network devices that could serve as footholds for espionage or disruptive operations.

State Actor Alignment

No state actor attribution is provided in this disclosure. However, MikroTik devices have historically been targeted by threat actors linked to Russian and Chinese intelligence services, as well as by botnet operators. The authentication bypass and unauthenticated remote code execution vectors identified (CVE-2026-67277, CVE-2026-67279, CVE-2026-67281) are consistent with vulnerability classes previously weaponized in campaigns attributed to APT28 (Fancy Bear) and Sandworm, both assessed to operate on behalf of Russian military intelligence. The coordinated disclosure process undertaken by CERT Polska, in cooperation with MikroTik, appears consistent with responsible vulnerability handling practices and EU cybersecurity policy frameworks, including the NIS2 Directive. There is no indication that these vulnerabilities were exploited in the wild prior to disclosure, though the technical sophistication required suggests that well-resourced actors could develop exploits rapidly. Organizations in sectors subject to sanctions or geopolitical tension—particularly energy, telecommunications, and government networks in NATO member states—should prioritize patching given the strategic value of router-level access for intelligence collection and pre-positioning.

Business Impacty pro region

The disclosure carries significant implications for European network security, particularly in Central and Eastern Europe where MikroTik devices enjoy substantial market penetration in small and medium enterprises, internet service providers, and municipal networks. Poland's role in identifying these flaws underscores the growing capacity of EU member state CERTs to conduct independent security research and contribute to collective defense. The vulnerabilities affect devices across critical infrastructure sectors, including energy distribution networks, telecommunications backhaul, and industrial control system (ICS) environments where MikroTik routers are frequently deployed as cost-effective edge devices. For NATO allies on the alliance's eastern flank—including the Baltic states, Romania, and Poland itself—the potential for adversary exploitation of these flaws to establish persistent access or conduct reconnaissance is a material concern. Globally, the widespread use of MikroTik in developing markets, particularly in Africa, Central Asia, and Southeast Asia, means that unpatched devices could be leveraged for botnet operations, espionage infrastructure, or as pivot points in supply chain compromises. The disclosure may prompt regulatory scrutiny of network equipment procurement practices and accelerate discussions within the EU regarding mandatory security standards for edge networking devices.

Forecast

If MikroTik device operators fail to apply patches promptly, it is likely that exploit code for the most severe vulnerabilities—particularly the unauthenticated remote code execution and authentication bypass flaws—will be integrated into both state-sponsored toolkits and commodity exploit frameworks within weeks. If threat actors linked to Russian intelligence services prioritize these vulnerabilities, targeting is likely to focus on telecommunications providers, energy sector networks, and government institutions in NATO member states, particularly those supporting Ukraine or hosting alliance infrastructure. If botnet operators weaponize these flaws, a surge in compromised MikroTik devices used for DDoS attacks, proxy networks, or cryptomining is probable, especially in regions with lower patch adoption rates. If European regulators respond to this disclosure with enhanced scrutiny, vendors of low-cost networking equipment may face increased compliance requirements under NIS2 and the Cyber Resilience Act, potentially reshaping procurement patterns in critical sectors. Organizations that delay patching beyond 30 days should anticipate elevated risk of compromise, particularly if they operate in geopolitically sensitive sectors or regions.