Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-67279 & CVE-2026-86060 Vulnerabilities

MikroTrick Chain Lets Attackers Take Over MikroTik Routers Without Passwords

MikroTrick chains CVE-2026-67279 and CVE-2026-86060 to let attackers take full control of internet-exposed MikroTik RouterOS devices without a password or SSH key.

Security researchers have detailed a two-vulnerability attack chain called MikroTrick that allows attackers to gain full administrative control of vulnerable MikroTik RouterOS devices without providing a password or valid SSH key.

CERT Polska confirmed that the technique has been actively exploited against routers with SSH exposed to the internet, with evidence of attacks dating back to at least September 2, 2026—one day before MikroTik released patches.

Two Vulnerabilities Create the Attack Chain

MikroTrick combines two RouterOS vulnerabilities:

Vulnerability Function
CVE-2026-67279 SSH state-machine flaw allowing an unauthenticated client to reach the command/session phase
CVE-2026-86060 Login argument-injection flaw enabling full administrative privileges

The first vulnerability breaks the expected SSH authentication sequence. By initiating SSH key renegotiation during authentication, an attacker can cause vulnerable RouterOS systems to proceed to the command phase without successfully verifying the user's identity.

CVE-2026-86060 then turns that access into full administrative control.

How MikroTrick Works

RouterOS passes the supplied SSH username to its /nova/bin/login process as a command-line argument.

Researchers discovered that an attacker could supply:

-2

as the username. Instead of treating -2 as a normal username, the login program interprets it as an option instructing it to read identity and privilege information from file descriptor 2.

The attacker can manipulate this process to supply a chosen username and a privilege value corresponding to full administrative access.

The overall attack chain becomes:

Internet-Exposed SSH → Authentication State Bypass → Crafted -2 Username → Privilege Manipulation → Full RouterOS Admin Access

No valid password or SSH private key is required.

Active Exploitation Observed

CERT Polska confirmed attackers were using the vulnerabilities against MikroTik routers with publicly accessible SSH services. Successful attacks were observed creating a highly privileged account named:

ops

Researchers also identified suspicious diagnostic-file generation and data transfers that indicated configuration information may have been copied from compromised devices.

Indicators associated with observed attacks include:

  • SSH login attempts using username -2
  • Unexpected ops administrator account
  • Source IP 82.192.72.4 in successful attacks
  • Source IP 103.102.31.18 in exploitation attempts
  • Unknown scripts or scheduler entries
  • Unexpected tunnels or proxy configurations
  • Unexplained .rif diagnostic files or fetch activity

CISA also added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10.

Patch MikroTik RouterOS Immediately

MikroTik released fixes in:

  • RouterOS 7.25beta3
  • RouterOS 7.24.2
  • RouterOS 7.23.4
  • RouterOS 6.49.21

Administrators should preferably install the latest available RouterOS release for their supported branch rather than stopping at the first patched version.

After updating, administrators should inspect the device's configuration for unauthorized users, scripts, scheduler tasks, proxies, tunnels and other suspicious modifications.

RouterOS's Flagged mechanism can identify some known signs of compromise, but CERT Polska warns that the absence of a Flagged status does not prove that a router is clean.

If compromise is detected, CERT Polska recommends isolating the router, preserving relevant evidence, factory-resetting it, rebuilding it from a trusted configuration and rotating passwords, SSH keys and other potentially exposed credentials.

Security Takeaway

MikroTrick is particularly dangerous because two separate weaknesses turn an unauthenticated SSH connection into full administrative control:

SSH Exposure → Authentication Bypass → Privilege Manipulation → Router Takeover

Organizations should immediately update internet-facing MikroTik devices and restrict SSH management access to trusted networks, VPNs or authorized management hosts.

Importantly, CVE-2026-67276 is a separate SSH authentication vulnerability and is not part of the MikroTrick chain detailed by CERT Polska. The confirmed chain consists of CVE-2026-67279 + CVE-2026-86060.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.