TechNewsReel
Live

MikroTrick: Attackers Hijack MikroTik Routers via SSH Bypass

A critical vulnerability chain allows unauthenticated remote attackers to gain full administrative control of internet-exposed RouterOS devices.

TechNewsReel Newsroom · September 6, 2026

Attackers are actively exploiting a critical vulnerability chain, dubbed "MikroTrick," to seize full administrative control of MikroTik routers. The flaw targets devices with internet-exposed SSH services, allowing remote actors to bypass security protocols without valid credentials.

The attack chain combines two high-severity vulnerabilities, both carrying a CVSS score of 9.2. The first, CVE-2026-67276, is an SSH authentication bypass caused by a failure in RouterOS to compare the entire RSA public key. This allows an attacker to impersonate a user if the username and public modulus are known. Once inside, the attacker leverages CVE-2026-86060, a privilege manipulation flaw where crafted usernames elevate the session to full administrative privileges. According to CERT Polska, combining these two flaws allows an attacker to "take full control of the device without authentication if the device supports remote access using the SSH protocol."

Discovery and Response

Successful exploitations of the MikroTrick chain have been observed since at least September 2, 2026. The vulnerabilities were identified through the OpenAI GTAC program, utilizing GPT-5.5-cyber and GPT-5.6-sol models. Following coordination by CERT Polska, MikroTik responded by releasing "silent" patches on September 3, 2026. The company initially withheld detailed explanations of the flaws to encourage users to update their systems rapidly before the technical details became public.

Industry Implications

This vulnerability represents a severe risk due to the ubiquity of MikroTik hardware. Because these routers are deeply integrated into both small business networks and carrier-grade ISP infrastructure, a remote, unauthenticated takeover could compromise the integrity of vast swaths of global network traffic. The ability for an external actor to gain root-level access to a gateway device allows for potential data interception, traffic redirection, and the creation of persistent backdoors within critical infrastructure.

Remediation and Next Steps

MikroTik has released official fixes to neutralize the MikroTrick chain. Administrators are urged to update to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 immediately. Network operators should also review their SSH exposure and consider restricting management access to trusted IP addresses to mitigate the risk of similar authentication bypasses in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.