< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 7 sources · 3 days · First seen · Last updated

MikroTik RouterOS MikroTrick exploitation

Overview

A critical zero-day vulnerability chain, referred to as ‘MikroTrick’, has been identified as actively exploiting MikroTik RouterOS devices. The exploit chain, which began appearing in the wild around September 2, 2026, targets internet-facing SSH services to bypass authentication and achieve full administrative control.

The attack primarily leverages two vulnerabilities, CVE-2026-67276 and CVE-2026-86060, which allow for unauthenticated remote access, device takeover, and the deployment of botnet payloads.

Subsequent reports confirmed that the exploitation involves a total of six vulnerabilities affecting various components, including the SSH server, bandwidth-test service, X.509 certificate handling, and the WebFig interface. Scans indicated that over 122,500 MikroTik devices with internet-reachable SSH were at risk, with significant concentrations found in Brazil, the United States, and Indonesia. MikroTik has since released several patched versions of RouterOS to remediate these flaws.

Entities

RouterOS · CERT Polska · MikroTik · Shadowserver Foundation

Timeline

  1. 3 days ago

    [TECHNOLOGY] 2 sources
    MikroTik patches vulnerabilities exploited in ‘MikroTrick’ attacks

    Attackers are actively exploiting the ‘MikroTrick’ vulnerability chain in MikroTik RouterOS to gain full administrative control of devices via exposed SSH services. Patches are now available.

  2. 6 days ago

    [TECHNOLOGY] 6 sources
    MikroTik RouterOS faces active exploitation via MikroTrick zero-day

    The ‘MikroTrick’ zero-day vulnerability chain is actively exploiting MikroTik RouterOS via SSH, allowing attackers to bypass authentication and gain full administrative control over internet-exposed devices.

Sources

cybernoz.com · flagthis.com · infoguerra.com.br · networkworld.com · security.nl · techjuice.pk · viakoo.com