← Back to Daily Briefing

The "MikroTrick" exploit chain targets MikroTik RouterOS, enabling complete device takeover via two chained vulnerabilities. Attackers utilize CVE-2026-67276 to bypass SSH authentication by exploiting flawed RSA public key handling, subsequently leveraging CVE-2026-86060 to escalate privileges via specially crafted usernames. Active exploitation since September 2, 2026, has exposed over 122,500 internet-facing devices. Remediation requires updating to firmware versions 7.24.2, 7.23.5, or 6.49.21 and conducting a comprehensive configuration audit to identify and remove attacker-created persistence mechanisms.

  • Exploit Chain Overview: The "MikroTrick" Campaign

    • Critical vulnerability chain targeting MikroTik RouterOS infrastructure, allowing full administrative control without valid credentials.
    • Threat landscape has shifted from "vulnerable" to "likely compromised" for devices with SSH exposed to the internet.
    • Estimated attack surface exceeds 122,500 exposed devices globally.
  • Vulnerability Mechanics: Technical Deep Dive

    • CVE-2026-67276: An authentication bypass flaw stemming from the incorrect handling of RSA public keys during the SSH handshake.
    • CVE-2026-86060: A privilege escalation vulnerability triggered by a specially crafted username during the login process.
    • The combination of these flaws allows an unauthenticated remote attacker to gain root-level access to the device.
  • Exploitation Status and Persistence

    • Active exploitation observed in the wild starting September 2, 2026.
    • Attackers maintain persistence by creating unauthorized administrative user accounts, ensuring access remains post-patching.
    • Documented post-exploitation activities include the modification of DNS settings, firewall rules, and the creation of remote-access tunnels.
  • Detection and Remediation Strategies

    • Immediate update to patched versions: 7.24.2, 7.23.5, or 6.49.21.
    • Execution of /system/device-mode/print to check if the device has been automatically "Flagged" as compromised.
    • Mandatory audit of all system user accounts to identify and purge rogue credentials.
  • Strategic Risk and Impact

    • High-risk profile facilitating large-scale network lateral movement and man-in-the-middle (MitM) traffic interception.
    • Underscores the critical vulnerability of edge infrastructure management interfaces exposed to the public internet.
    • Requires a two-step recovery process (update + audit) due to the persistence nature of the exploit.

Related posts

  1. Malware News — Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
  2. falconinternet.net — MikroTrick: Two Chained SSH CVEs Are Hijacking MikroTik Routers Across 122,500 Exposed Networks
  3. Malware News — MikroTik router flaws allow takeover without a password
  4. Industrial Cyber — CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain
  5. thehackernews.com — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
  6. Security Affairs — Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
  7. bleepingcomputer.com — Hackers exploit new MikroTik RouterOS flaws to hijack routers
  8. helpnetsecurity.com — Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
  9. socprime.com — CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
  10. Cybernews

LINK COPIED TO CLIPBOARD