Critical Unauthenticated Administrative Hijack Targeting MikroTik RouterOS via SSH
Published September 7, 2026
Since September 2, 2026, threat actors have been actively exploiting "MikroTrick," a zero-day vulnerability chain targeting MikroTik RouterOS. By leveraging internet-facing SSH services on port 22, attackers can bypass authentication mechanisms to achieve full administrative control over affected devices. This critical vulnerability allows for remote unauthenticated access, facilitating device takeover, lateral movement within protected networks, and the deployment of botnet payloads. Organizations must prioritize immediate patching to versions 7.24.2, 7.23.5, or 6.49.21 and conduct forensic audits of SSH logs and administrative user accounts to detect potential compromise.
- Vulnerability Overview: The 'MikroTrick' Chain
- Identified as a critical zero-day vulnerability chain targeting MikroTik RouterOS.
- Focuses on the Secure Shell (SSH) service as the primary entry point.
- Allows for remote, unauthenticated administrative-level access.
- Attack Vector & Technical Mechanics
- Exploits internet-exposed SSH services (Port 22).
- Bypasses standard authentication protocols to hijack administrative sessions.
- Active exploitation has been documented in the wild since early September 2026.
- Impact & Threat Landscape
- Severity is rated as Critical due to the potential for full device takeover.
- Serves as a high-value network pivot point for lateral movement.
- Facilitates large-scale botnet recruitment and Man-in-the-Middle (MitM) attacks.
- Detection & Forensic Investigation
- Analyze SSH authentication logs for successful logins lacking valid credentials.
- Audit the system for the unauthorized creation of administrative user accounts.
- Review configuration files for unexpected changes to routing or firewall rules.
- Remediation & Mitigation Strategies
- Update RouterOS to patched versions: 7.24.2, 7.23.5, or 6.49.21.
- Restrict SSH access to specific, trusted IP addresses via firewall rules.
- Disable SSH services on all public-facing interfaces where not strictly required.
Related posts
- thehackernews.com — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Cybersecurity News — Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access
- SANS Internet Storm Center — Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
- Malware News — Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
- datawater.com — MikroTik Called It a Quiet Patch. CERT Polska Calls It “MikroTrick” — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed
- xploitzone.com — MikroTrick RouterOS Critical Auth Bypass Lets Hackers Take Full Admin Control
- falconinternet.net — MikroTrick: Two Chained SSH CVEs Are Hijacking MikroTik Routers Across 122,500 Exposed Networks
- blackhatnews.tokyo — ハッカーがMikroTik RouterOSの「MikroTrick」脆弱性を積極的に悪用、ルーターを完全に乗っ取り
- Expert In the Cloud — Attackers Hijack MikroTik
- SOCFortress — MikroTrick: Active Exploitation of Critical MikroTik RouterOS Vulnerabilities
- Malware News — MikroTik router flaws allow takeover without a password
- Industrial Cyber — CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain
- Security Affairs — Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
- Cert
- Vuldb
- Github
- Infosecurity-magazine
- Vulncheck
- Ground
- Startupfortune
- Forum
- Mikrotik
- cyberinsider.com — MikroTik RouterOS bugs actively exploited in device takeover attacks
- bleepingcomputer.com — Hackers exploit new MikroTik RouterOS flaws to hijack routers
- helpnetsecurity.com — Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
- socprime.com — CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
- Cycognito
- Cybernews
- Labs
- Labs
- Malwarebytes
- Esecurityplanet