# MikroTik RouterOS MikroTrick exploitation

> Live situation record from CLSTR: https://clstr.news/situations/mikrotik-routeros-mikrotrick-exploitation
> Updated: 2026-09-09T00:00:00.000Z. Sources: 7. Developments: 2.

A critical zero-day vulnerability chain, referred to as ‘MikroTrick’, has been identified as actively exploiting MikroTik RouterOS devices. The exploit chain, which began appearing in the wild around September 2, 2026, targets internet-facing SSH services to bypass authentication and achieve full administrative control. 

The attack primarily leverages two vulnerabilities, CVE-2026-67276 and CVE-2026-86060, which allow for unauthenticated remote access, device takeover, and the deployment of botnet payloads. 

Subsequent reports confirmed that the exploitation involves a total of six vulnerabilities affecting various components, including the SSH server, bandwidth-test service, X.509 certificate handling, and the WebFig interface. Scans indicated that over 122,500 MikroTik devices with internet-reachable SSH were at risk, with significant concentrations found in Brazil, the United States, and Indonesia. MikroTik has since released several patched versions of RouterOS to remediate these flaws.

## Timeline

### 2026-09-09: MikroTik patches vulnerabilities exploited in ‘MikroTrick’ attacks

Attackers are actively exploiting the ‘MikroTrick’ vulnerability chain in MikroTik RouterOS to gain full administrative control of devices via exposed SSH services. Patches are now available.

2 sources. https://clstr.news/cluster/mikrotik-patches-vulnerabilities-exploited-in-mikrotrick-attacks

### 2026-09-06: MikroTik RouterOS faces active exploitation via MikroTrick zero-day

The ‘MikroTrick’ zero-day vulnerability chain is actively exploiting MikroTik RouterOS via SSH, allowing attackers to bypass authentication and gain full administrative control over internet-exposed devices.

6 sources. https://clstr.news/cluster/mikrotik-routeros-faces-active-exploitation-via-mikrotrick-zero-day

---
Cite as: MikroTik RouterOS MikroTrick exploitation. CLSTR, https://clstr.news/situations/mikrotik-routeros-mikrotrick-exploitation
