Critical

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News
Actively Exploited

Overview

Researchers have identified a serious vulnerability affecting MikroTik routers that allows attackers to gain full administrative control without needing a password or SSH key. Known as the MikroTrick chain, this issue arises from two flaws in the RouterOS software: an SSH state-machine vulnerability (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060). These vulnerabilities can be exploited on routers that are exposed to the internet, putting numerous devices at risk. Users of MikroTik routers should take immediate action to secure their devices, as the potential for unauthorized access could lead to significant data breaches or network disruptions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: MikroTik RouterOS devices, specifically those exposed to the internet and running vulnerable versions affected by CVE-2026-67279 and CVE-2026-86060.
  • Action Required: Users should immediately update their MikroTik RouterOS to the latest version that addresses these vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Impact

MikroTik RouterOS devices, specifically those exposed to the internet and running vulnerable versions affected by CVE-2026-67279 and CVE-2026-86060.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should immediately update their MikroTik RouterOS to the latest version that addresses these vulnerabilities. Additionally, it is recommended to implement firewall rules to limit exposure of SSH services to the internet and to change default configurations that may be susceptible to these types of attacks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability.

Related Coverage

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputer

A critical vulnerability in WordPress, identified as CVE-2026-87902, is currently being exploited by hackers. Initially, attackers were probing for sites that were vulnerable, but they have now escalated to exploiting the flaw to write files to disk that can execute shell commands when accessed. This puts numerous WordPress installations at risk, particularly those running outdated or unpatched versions of the software. Users and website administrators need to take this threat seriously, as the exploitation can lead to unauthorized access and control over affected sites. This situation underscores the importance of timely updates and security measures in maintaining website integrity.

Sep 23, 2026

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

darkreading

In the first half of 2026, the United Arab Emirates and Saudi Arabia faced a significant increase in cyberattacks, accounting for half of all incidents reported in the Gulf region. These attacks have become more complex, posing serious challenges for cybersecurity teams in both countries. The rise in incidents affects various sectors, raising concerns about the security of sensitive data and critical infrastructure. This situation highlights the urgent need for enhanced cybersecurity measures and collaboration among nations to combat these evolving threats. The implications of these attacks could be far-reaching, affecting not only businesses but also national security and public trust in digital systems.

Sep 23, 2026

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer

A recent security analysis reveals that a Kubernetes user with limited permissions can exploit a flaw in Google Kubernetes Config Connector to gain control over an entire Google Cloud organization. This issue stems from a confused deputy problem, where the permissions granted to the Config Connector can be misused through a single Kubernetes YAML file. This vulnerability poses a significant risk because it allows unauthorized users to escalate their privileges and potentially compromise sensitive resources across the organization. Organizations using Google Cloud and Kubernetes need to be aware of this risk and take measures to secure their configurations. The implications of such a breach could be severe, affecting data integrity and access control.

Sep 23, 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News

Threat actors have compromised two legitimate MemTensor packages on the npm and PyPI repositories to distribute a malicious program called sckit. This implant targets Windows, Linux, and macOS systems and is designed to steal credentials. Researchers from Aikido, SafeDep, Socket, and StepSecurity have reported on the affected libraries, particularly the @memtensor/memos-cloud-openclaw-plugin versions. This incident raises significant security concerns for developers and users who may have unknowingly installed these compromised packages. It's crucial for affected users to take immediate action to safeguard their systems.

Sep 23, 2026

Arista patches actively exploited VeloCloud Orchestrator zero-day

BleepingComputer

Arista Networks has addressed a zero-day vulnerability in the VeloCloud Orchestrator (VCO) On-Prem deployments, which is currently being exploited by attackers. This flaw poses a significant risk, as it allows unauthorized access to the system, potentially compromising sensitive data and network operations. Users of the VCO should apply the security patches released by Arista immediately to protect their systems. The urgency of this patching process is underscored by the fact that the vulnerability is actively being exploited in the wild. Organizations relying on VeloCloud Orchestrator must prioritize this update to mitigate the risk of an attack and safeguard their network infrastructure.

Sep 23, 2026

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News

A new vulnerability in cPanel's CalDAV and CardDAV service allows anyone with a cPanel hosting account to execute code with root privileges, giving them full control of the server. This serious flaw was disclosed on September 22 and affects users who rely on cPanel for their web hosting services. Additionally, a separate issue in the WP Toolkit plugin enables account holders to modify databases belonging to other users, raising further security concerns. cPanel has responded by releasing fixed versions to address both vulnerabilities, underscoring the need for users to update their systems promptly to prevent potential exploitation.

Sep 23, 2026