A critical exploit chain, dubbed "MikroTrick," targets MikroTik RouterOS by combining an SSH authentication bypass (CVE-2026-67276) with an unauthenticated file-read vulnerability via the WebFig interface (CVE-2026-67281). This chain allows remote attackers to achieve full administrative takeover of internet-exposed devices without possessing legitimate RSA private keys. Despite MikroTik attempting a "silent" security patch on September 3, 2026, intelligence from CERT Polska confirms active exploitation was detected as early as September 2, 2026. This 24-hour discrepancy indicates that threat actors successfully bypassed authentication and gained control of target infrastructure prior to the availability of any vendor mitigation.
-
Vulnerability Mechanics: The MikroTrick Chain
- CVE-2026-67276 (SSH Bypass): A high-severity flaw (CVSS 9.2) that enables attackers to authenticate as an existing user without a valid RSA private key.
- CVE-2026-67281 (WebFig File Read): An unauthenticated vulnerability within the WebFig interface allowing for remote file access.
- Chained Impact: The synergy of these two flaws facilitates complete, unauthorized administrative access to the RouterOS environment.
-
Exploitation Status and Timeline Discrepancy
- Active Zero-Day Exploitation: CERT Polska confirmed that the MikroTrick chain was being actively utilized in the wild during early September 2026.
- The "Silent Patch" Failure: MikroTik's attempt to release a non-disclosed patch on September 3 failed to outpace attackers, who were active 24 hours prior.
- Security Through Obscurity: The incident highlights the risks of delayed public disclosure when active exploitation is already underway.
-
Attack Surface and Operational Impact
- Targeted Vectors: Internet-exposed SSH services and WebFig management interfaces are the primary entry points.
- Scope of Compromise: Successful exploitation leads to full administrative takeover of the router.
- Downstream Risks: Compromised routers allow for traffic interception, man-in-the-middle (MITM) attacks, and lateral movement within the protected network.
-
Mitigation and Defensive Recommendations
- Immediate Patching: Deploy the latest MikroTik RouterOS security updates immediately to remediate both CVEs.
- Attack Surface Reduction: Disable SSH and WebFig management on all internet-facing interfaces.
- Access Control: Implement strict firewall rules and restrict management interface access to known, trusted IP ranges or VPNs.
- Log Auditing: Review system logs for anomalous SSH login patterns or unauthorized file access attempts via WebFig.
Related posts
- datawater.com — MikroTik Called It a Quiet Patch. CERT Polska Calls It “MikroTrick” — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed
- blackhatnews.tokyo — ハッカーがMikroTik RouterOSの「MikroTrick」脆弱性を積極的に悪用、ルーターを完全に乗っ取り
- Expert In the Cloud — Attackers Hijack MikroTik
- SOCFortress — MikroTrick: Active Exploitation of Critical MikroTik RouterOS Vulnerabilities
- thehackernews.com — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Cert
- Mikrotik
- cyberinsider.com — MikroTik RouterOS bugs actively exploited in device takeover attacks
- bleepingcomputer.com — Hackers exploit new MikroTik RouterOS flaws to hijack routers
- socprime.com — CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
- Cycognito
- Cybernews
- Labs