CERT Polska confirmed active attacks against internet-facing MikroTik RouterOS devices on September 5, 2026. Attackers chain two flaws, named MikroTrick, to seize full control over SSH without a password. This MikroTik RouterOS vulnerability chain is exploited in the wild, and public proof-of-concept exploit code is already available.
- Total: 6 CVEs
- Severity: 2 Critical · 2 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.2 (Critical · CVSSv4) — CVE-2026-67276
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-67276 | 9.2 | SSH user impersonation possible in | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
| CVE-2026-86060 | 9.2 | SSH session privilege manipulation via a crafted username in | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
| CVE-2026-67277 | 8.8 | Kernel memory disclosure and denial of service in btest service | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
| CVE-2026-67281 | 8.7 | Unauthenticated file read in | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
| CVE-2026-67279 | 6.9 | SSH Pre-Authentication Rekey State Bypass in | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
| CVE-2026-67278 | 6.3 | TLS server impersonation possible in | 7.24.2, 7.23.4, 6.49.21 | Exploited in the wild |
Why this matters
MikroTik routers sit at the edge of countless networks worldwide. So a full takeover exposes every device behind them. The MikroTrick chain needs no username, no password, and no private key. CERT Polska confirmed real attacks and published full technical details. Both facts raise the urgency sharply.
The danger is not theoretical. CERT Polska states it has “confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks.”
How the attack works
The MikroTrick chain combines two SSH flaws. The first, CVE-2026-67276, is a public-key authentication bypass. RouterOS checks the key type and modulus but skips the exponent during key matching. As a result, an attacker who knows an authorized user’s public modulus can forge a valid signature. That opens an SSH channel as the target user, without the private key.
The second flaw, CVE-2026-86060, escalates privileges. It abuses a crafted username in the SSH login path to alter the RouterOS policy mask. Chained together, the two flaws grant full administrative privileges in the RouterOS system. Both carry a CVSS score of 9.2.
Four more flaws in the set
CERT Polska disclosed six bugs in total. CVE-2026-67279 allows unauthenticated file operations after an SSH rekey. CVE-2026-67281 is an unauthenticated WebFig file-read that can disclose credential stores. CVE-2026-67277 targets the bandwidth-test service and can restart the kernel. CVE-2026-67278 enables TLS server impersonation through forged certificates.
Exploitation status
The exploitation status is clear and confirmed. CERT Polska observed successful attacks since at least September 2, 2026. The attackers created a highly privileged account named “ops” on compromised devices. Beyond that, public proof-of-concept exploit code for the authentication bypass is now available. Independent researchers have also published a reverse-engineering analysis of the silent patch.
Affected versions
The flaws affect a wide range of RouterOS builds across the 6.x and 7.x branches. MikroTik shipped fixes in 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. The vendor even sent a first-ever push notification to users of the MikroTik mobile app. Review the MikroTik security bulletin to confirm your build.
Patch and mitigation steps
Update RouterOS immediately to a fixed release. The 6.49.21 long-term release covers older deployments. After patching, check logs for compromise messages and the “Flagged” marker. Also review the configuration for unknown users, scripts, scheduler tasks, and tunnels.
If you cannot patch at once, reduce exposure. Block SSH, WebFig, and the bandwidth-test service from untrusted networks. Avoid initiating TLS connections from unpatched devices. Note that these steps are temporary and do not replace the update. If a device shows the “Flagged” marker, treat it as compromised and isolate it.
Public analysis and proof-of-concept
This premium content is securely locked. You must upgrade your subscription to access the full threat intelligence report, including detailed mitigation steps, deep-dive analysis, and active exploitation metrics. Your attempt to inspect the DOM will only reveal this placeholder text. Please support our work to read the actual coverage.
Unlock Premium Threat Intelligence
This is a premium content. Upgrade to Pro or Team to unlock full access and remove all reading restrictions.