This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Updated: Attackers Intensify Efforts to Compromise MikroTik Routers
Polish CERT team CERT Polska identified and coordinated the public disclosure of six MikroTik RouterOS vulnerabilities. CVE-2026-86060 – SSH session privilege manipulation via specially crafted username (CVSS: 9.2). RouterOS SSH login mechanism mishandled usernames starting with unauthorized characters. CVE-2026-67277 – Memory data leak and system overload via bandwidth-test (CVSS: 8.8). The bandwidth-test service allowed unauthenticated connections to reach privileged states, potentially leading to kernel memory leaks or remote denial-of-service (DoS) attacks causing system restart. Immediate router updates are necessary to fix these vulnerabilities. After updating, check device logs for signs of compromise, verify the 'Flagged' status with the appropriate command, and review configurations for unknown users, scripts, or changes. More information and detailed research can be found at: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ MikroTik security bulletin: https://mikrotik.com/supportsec/september-2026-vulnerability/ MikroTik info on 'Flagged' marker: https://manual.mikrotik.com/docs/system-information-and-utilities/device-mode/#flagged-status Tutorial on creating Supout.rif file: https://help.mikrotik.com/docs/spaces/ROS/pages/328106/Supout.rif