The "MikroTrick" exploit chain targets MikroTik RouterOS, enabling complete device takeover via two chained vulnerabilities. Attackers utilize CVE-2026-67276 to bypass SSH authentication by exploiting flawed RSA public key handling, subsequently leveraging CVE-2026-86060 to escalate privileges via specially crafted usernames. Active exploitation since September 2, 2026, has exposed over 122,500 internet-facing devices. Remediation requires updating to firmware versions 7.24.2, 7.23.5, or 6.49.21 and conducting a comprehensive configuration audit to identify and remove attacker-created persistence mechanisms.
-
Exploit Chain Overview: The "MikroTrick" Campaign
- Critical vulnerability chain targeting MikroTik RouterOS infrastructure, allowing full administrative control without valid credentials.
- Threat landscape has shifted from "vulnerable" to "likely compromised" for devices with SSH exposed to the internet.
- Estimated attack surface exceeds 122,500 exposed devices globally.
-
Vulnerability Mechanics: Technical Deep Dive
- CVE-2026-67276: An authentication bypass flaw stemming from the incorrect handling of RSA public keys during the SSH handshake.
- CVE-2026-86060: A privilege escalation vulnerability triggered by a specially crafted username during the login process.
- The combination of these flaws allows an unauthenticated remote attacker to gain root-level access to the device.
-
Exploitation Status and Persistence
- Active exploitation observed in the wild starting September 2, 2026.
- Attackers maintain persistence by creating unauthorized administrative user accounts, ensuring access remains post-patching.
- Documented post-exploitation activities include the modification of DNS settings, firewall rules, and the creation of remote-access tunnels.
-
Detection and Remediation Strategies
- Immediate update to patched versions: 7.24.2, 7.23.5, or 6.49.21.
- Execution of
/system/device-mode/printto check if the device has been automatically "Flagged" as compromised. - Mandatory audit of all system user accounts to identify and purge rogue credentials.
-
Strategic Risk and Impact
- High-risk profile facilitating large-scale network lateral movement and man-in-the-middle (MitM) traffic interception.
- Underscores the critical vulnerability of edge infrastructure management interfaces exposed to the public internet.
- Requires a two-step recovery process (update + audit) due to the persistence nature of the exploit.
Related posts
- Malware News — Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
- falconinternet.net — MikroTrick: Two Chained SSH CVEs Are Hijacking MikroTik Routers Across 122,500 Exposed Networks
- Malware News — MikroTik router flaws allow takeover without a password
- Industrial Cyber — CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain
- thehackernews.com — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Security Affairs — Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
- bleepingcomputer.com — Hackers exploit new MikroTik RouterOS flaws to hijack routers
- helpnetsecurity.com — Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
- socprime.com — CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks
- Cybernews