< Back to all clusters
[TECHNOLOGY] · United States, Brazil, Indonesia · 2 sources

started · updated

MikroTik patches vulnerabilities exploited in ‘MikroTrick’ attacks

CERT Polska has confirmed the active exploitation of six vulnerabilities in MikroTik RouterOS, including a two-flaw chain known as ‘MikroTrick’. This exploit chain allows attackers to gain full administrative control of internet-accessible devices without authentication when SSH services are exposed to public networks.

The vulnerabilities affect several components, including the SSH server and client, the bandwidth-test service, X.509 certificate handling, and the WebFig interface. Among the most critical flaws are CVE-2026-67276 and CVE-2026-86060, both rated with a CVSS score of 9.2. These flaws involve SSH authentication bypass and a crafted-username vulnerability that can grant full administrative privileges.

Scans by the Shadowserver Foundation indicate that over 122,500 MikroTik devices have SSH reachable from the internet, with high concentrations in Brazil, the United States, and Indonesia. MikroTik has released patches in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Administrators are urged to update immediately and inspect devices for unauthorized users, scripts, or configuration changes.

Entities

CERT Polska · MikroTik · RouterOS · Shadowserver Foundation