#MikroTik
All CosmicBytez Labs articles tagged #MikroTik, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
An unauthenticated SSH workflow-bypass in MikroTik RouterOS chains with CVE-2026-86060 for full router takeover; CISA added it to KEV on Sept 25.
- Security
CVE-2026-86060: MikroTik RouterOS SSH Privilege Escalation
Unauthenticated attackers can escalate to full admin control on MikroTik RouterOS via a crafted SSH username; CISA lists it as actively exploited.
- Newsletter
Weekly Digest — Issue #34
Adobe rushes an emergency patch as Magento's 'StyleSmuggler' zero-day backdoors stores, an F5 BIG-IP rootkit hides fileless, and JetBrains leaks AWS keys.
- News
Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack, and More
This week's roundup: a sixth Chrome zero-day, mass MikroTik router hijacking, a Coder registry compromise, and N-able's third N-central RCE.
- News
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.