Intel Hub

Threat intel

A chained SSH flaw gave attackers full admin on MikroTik routers, no password needed.

CERT Polska traced a two-bug SSH exploit chain, nicknamed MikroTrick, against internet-exposed MikroTik RouterOS devices back to September 2. CISA added the lead flaw, CVE-2026-67279, to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 28 to patch.

CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities catalog on September 25, giving federal agencies until September 28 to patch it. The flaw's discoverer, CERT Polska, said it is being chained in the wild with a second bug, CVE-2026-86060, to grant attackers full administrative access to MikroTik RouterOS devices with no password, no SSH key, and no completed authentication. Security firm Bishop Fox independently reproduced the full takeover on RouterOS 7.x builds.


MikroTik routers sit at the network edge for internet service providers, small businesses, and hobbyists worldwide, and RouterOS ships with extensive remote-management features that make its SSH service a natural target. CERT Polska traced successful attacks against internet-exposed devices back to at least September 2, a day before MikroTik shipped patches on September 3. Researcher Emilio Gallegos described the chain, dubbed MikroTrick, as combining two failures at different trust boundaries, exposing a broader design problem in which features meant for local administrators become reachable from the open internet.


CVE-2026-67279 is an SSH protocol flaw: when a client requests a rekey, RouterOS's SSH server can move into the connection phase without completing authentication, then accept an exec request that allows unauthenticated file operations inside RouterOS's managed file namespace. Chained with CVE-2026-86060, an argument-injection flaw in the SSH login path that lets an attacker alter the trusted policy mask, the pair escalates to full administrative console access. CISA separately catalogued a related flaw, CVE-2026-67277 (CVSS 8.8), covering unauthenticated kernel memory disclosure through RouterOS's btest tool. CERT Polska has traced confirmed attack traffic to the IP addresses 82.192.72.4 and 103.102.31.18.


MikroTik shipped fixes on September 3 in RouterOS 6.49.21, 7.23.4 long-term, and 7.24.2 stable; anything older remains exposed if SSH is reachable from the internet. RouterOS blocks SSH from the internet by default, so exposure generally means an administrator opened it manually. CISA and CERT Polska recommend upgrading immediately, disabling SSH access from untrusted networks in favor of a VPN for management, restricting bandwidth-test and WWW/WWW-SSL services from untrusted addresses, and hunting logs for repeated "-2" login failures, unexpected "ops" account creation, or RouterOS-flagged entries. Devices suspected of compromise should be isolated and factory-reset rather than restored from backup, since a restore can reintroduce an attacker-modified configuration.

Sign-in required.

The full encrypted event log and the mitigation steps are available after sign-in.