< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

MikroTik RouterOS faces active exploitation via MikroTrick zero-day

A critical zero-day vulnerability chain, dubbed ‘MikroTrick’, is being actively exploited against MikroTik RouterOS devices. The attack chain, which has been observed in the wild since September 2, 2026, targets internet-facing SSH services to bypass authentication and achieve full administrative control over affected devices.

The exploit combines two specific vulnerabilities: CVE-2026-67276, an SSH authentication bypass involving RSA public key verification, and CVE-2026-86060, an SSH session privilege escalation. By leveraging these flaws, attackers can gain unauthenticated remote access, allowing for device takeover, lateral movement within networks, and the deployment of botnet payloads.

CERT Polska and cybersecurity experts recommend that users with SSH exposed to the internet treat their devices as potentially compromised. Immediate remediation steps include updating RouterOS to patched versions 7.25beta3, 7.24.2, 7.23.5, 7.23.4, or 6.49.21. Security professionals are advised to audit SSH logs for unauthorized logins and check for the creation of unexpected administrative accounts.

Entities

CERT Polska · MikroTik · RouterOS