MikroTik Patches Critical Flaws Chained to Hack Routers
MikroTik has released critical patches to address six vulnerabilities in RouterOS, with two now confirmed to be actively exploited by attackers. The ‘MikroTrick’ campaign, leveraging these flaws, allows attackers to take full control of devices with accessible SSH services. Users are urged to update immediately to prevent exploitation.
MikroTik, a network equipment manufacturer, has released security updates to address six vulnerabilities within its RouterOS software. CERT Poland has warned that two of these flaws, dubbed ‘MikroTrick,’ are currently being exploited in the wild. These vulnerabilities allow attackers to bypass authentication and gain complete control over devices whose SSH service is accessible from public networks. CERT Poland reports that hackers have been chaining these vulnerabilities since at least September 2nd, utilizing accounts such as ‘ops’ to achieve this level of control.
The vulnerabilities include CVE-2026-67276 (CVSS score of 9.2), an SSH authentication bypass bug; CVE-2026-86060 (CVSS score of 9.2), an SSH session privilege manipulation issue; and CVE-2026-67277 (CVSS score of 8.8), a memory disclosure and denial-of-service weakness. Additionally, updates address CVE-2026-67278 (enables TLS server impersonation), CVE-2026-67279 (allows unauthenticated attackers to tamper with files, including configuration files), and CVE-2026-67281 (allows attackers to disclose root-owned files, including configuration stores).
The Shadowserver Foundation detected over 120,000 MikroTik devices with SSH accessible from the internet during a 24-hour scan window on September 5th. Users are advised to update their MikroTik routers to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible. The presence of any of these artifacts indicates an attempt to exploit the vulnerabilities and must be investigated immediately; at the same time, the absence of the traces mentioned above does not rule out unauthorized activity.