MikroTik Patches Critical Flaws Chained to Hack Routers
MikroTik patched six vulnerabilities in RouterOS, two of which are actively exploited in the wild under the "MikroTrick" attack chain CVE-2026-67276 and CVE-2026-86060 (both CVSS 9.2) enable SSH authentication bypass and privilege manipulation, allowing full device takeover Over 120,000 MikroTik devices with publicly accessible SSH were identified by Shadowserver Foundation, indicating a massive attack surface CERT Poland confirmed the MikroTrick chain has been active since at least September 2,
Analysis
TL;DR
- MikroTik patched six vulnerabilities in RouterOS, two of which are actively exploited in the wild under the "MikroTrick" attack chain
- CVE-2026-67276 and CVE-2026-86060 (both CVSS 9.2) enable SSH authentication bypass and privilege manipulation, allowing full device takeover
- Over 120,000 MikroTik devices with publicly accessible SSH were identified by Shadowserver Foundation, indicating a massive attack surface
- CERT Poland confirmed the MikroTrick chain has been active since at least September 2, with attackers creating a persistent "ops" account on compromised devices
- Immediate patching to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 is critical, along with blocking SSH from untrusted sources
Why It Matters
This is a critical, actively exploited vulnerability affecting a significant installed base of network infrastructure devices, making it a high-priority concern for any organization relying on MikroTik routers. The combination of authentication bypass and privilege escalation in SSH means attackers can gain full control with minimal effort, and the sheer scale of exposed devices (120,000+) amplifies the risk of widespread compromise and botnet recruitment.
Technical Details
- CVE-2026-67276 (CVSS 9.2): SSH authentication bypass vulnerability allowing attackers to gain unauthorized access without valid credentials
- CVE-2026-86060 (CVSS 9.2): SSH session privilege manipulation enabling attackers to escalate privileges after initial access
- CVE-2026-67277 (CVSS 8.8): Memory disclosure and denial-of-service weakness in the SSH subsystem
- CVE-2026-67278: TLS server impersonation vulnerability
- CVE-2026-67279: Unauthenticated file tampering, including configuration files
- CVE-2026-67281: Root-owned file disclosure, including configuration stores
- MikroTrick chain: Two vulnerabilities combined to bypass SSH authentication and manipulate privileges, creating a persistent backdoor account named "ops"
- Patch versions: RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21
- Attack indicators: Source IPs 82.192.72.4 and 103.102.31.18; "Flagged" entries in device logs; "ops" user account creation
Industry Insight
- Organizations with MikroTik infrastructure should treat this as an emergency, prioritizing immediate patching and SSH access restriction, as the active exploitation chain is straightforward and widely weaponized
- The 120,000+ exposed devices highlight the ongoing risk of default or misconfigured SSH exposure on network infrastructure, reinforcing the need for automated attack surface monitoring and strict network segmentation policies
- Vendor advisory quality matters—MikroTik's "scarce" advisory underscores the importance of supplementing vendor guidance with third-party sources like CERT Poland and Shadowserver for comprehensive threat intelligence and detection indicators
Disclaimer: The above content is generated by AI and is for reference only.