MikroTrick Chain Lets Attackers Take Over MikroTik Routers Without Passwords
MikroTrick chains CVE-2026-67279 and CVE-2026-86060 to let attackers take full control of internet-exposed MikroTik RouterOS devices without a password or SSH key.

Security researchers have detailed a two-vulnerability attack chain called MikroTrick that allows attackers to gain full administrative control of vulnerable MikroTik RouterOS devices without providing a password or valid SSH key.
CERT Polska confirmed that the technique has been actively exploited against routers with SSH exposed to the internet, with evidence of attacks dating back to at least September 2, 2026—one day before MikroTik released patches.
Two Vulnerabilities Create the Attack Chain
MikroTrick combines two RouterOS vulnerabilities:
| Vulnerability | Function |
|---|---|
| CVE-2026-67279 | SSH state-machine flaw allowing an unauthenticated client to reach the command/session phase |
| CVE-2026-86060 | Login argument-injection flaw enabling full administrative privileges |
The first vulnerability breaks the expected SSH authentication sequence. By initiating SSH key renegotiation during authentication, an attacker can cause vulnerable RouterOS systems to proceed to the command phase without successfully verifying the user's identity.
CVE-2026-86060 then turns that access into full administrative control.
How MikroTrick Works
RouterOS passes the supplied SSH username to its /nova/bin/login process as a command-line argument.
Researchers discovered that an attacker could supply:
-2
as the username. Instead of treating -2 as a normal username, the login program interprets it as an option instructing it to read identity and privilege information from file descriptor 2.
The attacker can manipulate this process to supply a chosen username and a privilege value corresponding to full administrative access.
The overall attack chain becomes:
Internet-Exposed SSH → Authentication State Bypass → Crafted -2 Username → Privilege Manipulation → Full RouterOS Admin Access
No valid password or SSH private key is required.
Active Exploitation Observed
CERT Polska confirmed attackers were using the vulnerabilities against MikroTik routers with publicly accessible SSH services. Successful attacks were observed creating a highly privileged account named:
ops
Researchers also identified suspicious diagnostic-file generation and data transfers that indicated configuration information may have been copied from compromised devices.
Indicators associated with observed attacks include:
- SSH login attempts using username
-2 - Unexpected
opsadministrator account - Source IP
82.192.72.4in successful attacks - Source IP
103.102.31.18in exploitation attempts - Unknown scripts or scheduler entries
- Unexpected tunnels or proxy configurations
- Unexplained
.rifdiagnostic files orfetchactivity
CISA also added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10.
Patch MikroTik RouterOS Immediately
MikroTik released fixes in:
- RouterOS 7.25beta3
- RouterOS 7.24.2
- RouterOS 7.23.4
- RouterOS 6.49.21
Administrators should preferably install the latest available RouterOS release for their supported branch rather than stopping at the first patched version.
After updating, administrators should inspect the device's configuration for unauthorized users, scripts, scheduler tasks, proxies, tunnels and other suspicious modifications.
RouterOS's Flagged mechanism can identify some known signs of compromise, but CERT Polska warns that the absence of a Flagged status does not prove that a router is clean.
If compromise is detected, CERT Polska recommends isolating the router, preserving relevant evidence, factory-resetting it, rebuilding it from a trusted configuration and rotating passwords, SSH keys and other potentially exposed credentials.
Security Takeaway
MikroTrick is particularly dangerous because two separate weaknesses turn an unauthenticated SSH connection into full administrative control:
SSH Exposure → Authentication Bypass → Privilege Manipulation → Router Takeover
Organizations should immediately update internet-facing MikroTik devices and restrict SSH management access to trusted networks, VPNs or authorized management hosts.
Importantly, CVE-2026-67276 is a separate SSH authentication vulnerability and is not part of the MikroTrick chain detailed by CERT Polska. The confirmed chain consists of CVE-2026-67279 + CVE-2026-86060.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


