Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 7 sources · 3 days · First seen · Last updated
MikroTik RouterOS MikroTrick exploitation
Overview
A critical zero-day vulnerability chain, referred to as ‘MikroTrick’, has been identified as actively exploiting MikroTik RouterOS devices. The exploit chain, which began appearing in the wild around September 2, 2026, targets internet-facing SSH services to bypass authentication and achieve full administrative control.
The attack primarily leverages two vulnerabilities, CVE-2026-67276 and CVE-2026-86060, which allow for unauthenticated remote access, device takeover, and the deployment of botnet payloads.
Subsequent reports confirmed that the exploitation involves a total of six vulnerabilities affecting various components, including the SSH server, bandwidth-test service, X.509 certificate handling, and the WebFig interface. Scans indicated that over 122,500 MikroTik devices with internet-reachable SSH were at risk, with significant concentrations found in Brazil, the United States, and Indonesia. MikroTik has since released several patched versions of RouterOS to remediate these flaws.
Entities
Timeline
-
3 days ago
[TECHNOLOGY] 2 sourcesMikroTik patches vulnerabilities exploited in ‘MikroTrick’ attacksAttackers are actively exploiting the ‘MikroTrick’ vulnerability chain in MikroTik RouterOS to gain full administrative control of devices via exposed SSH services. Patches are now available.
-
6 days ago
[TECHNOLOGY] 6 sourcesMikroTik RouterOS faces active exploitation via MikroTrick zero-dayThe ‘MikroTrick’ zero-day vulnerability chain is actively exploiting MikroTik RouterOS via SSH, allowing attackers to bypass authentication and gain full administrative control over internet-exposed devices.
Sources
cybernoz.com · flagthis.com · infoguerra.com.br · networkworld.com · security.nl · techjuice.pk · viakoo.com