MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Overview
Researchers have identified a serious vulnerability affecting MikroTik routers that allows attackers to gain full administrative control without needing a password or SSH key. Known as the MikroTrick chain, this issue arises from two flaws in the RouterOS software: an SSH state-machine vulnerability (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060). These vulnerabilities can be exploited on routers that are exposed to the internet, putting numerous devices at risk. Users of MikroTik routers should take immediate action to secure their devices, as the potential for unauthorized access could lead to significant data breaches or network disruptions.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: MikroTik RouterOS devices, specifically those exposed to the internet and running vulnerable versions affected by CVE-2026-67279 and CVE-2026-86060.
- Action Required: Users should immediately update their MikroTik RouterOS to the latest version that addresses these vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Impact
MikroTik RouterOS devices, specifically those exposed to the internet and running vulnerable versions affected by CVE-2026-67279 and CVE-2026-86060.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should immediately update their MikroTik RouterOS to the latest version that addresses these vulnerabilities. Additionally, it is recommended to implement firewall rules to limit exposure of SSH services to the internet and to change default configurations that may be susceptible to these types of attacks.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability.