www.securityweek.com 8 Sept 2026, 11:15 UTC

MikroTik Patches Exploited RouterOS Flaws in MikrTrick Attack Chain

MikroTik Patches Exploited RouterOS Flaws in MikrTrick Attack Chain
CyberSIXT Evidence Panel

MIKROTIK has released patches for six vulnerabilities in RouterOS, with two of the flaws reportedly being exploited in the wild. The security gaps, collectively dubbed MikrTrick, allow attackers to bypass authentication, gain control of devices, and tamper with configuration files. CERT Poland confirms that two of the patched issues have been chained together to compromise routers whose SSH service is reachable from the public Internet.

MikroTik’s advisory urges immediate updating and notes that blocking SSH from untrusted sources can mitigate risk, while compromised devices may show a “Flagged” entry in the log.

The advisory highlights three CVEs: CVE-2026-67276 (SSH authentication bypass, CVSS 9.2), CVE-2026-86060 (SSH session privilege manipulation, CVSS 9.2), and CVE-2026-67277 (memory disclosure and denial-of-service, CVSS 8.8). In addition, the patches also address CVE-2026-67278 (TLS server impersonation), CVE-2026-67279 (unauthenticated attackers tampering with files, including configuration files), and CVE-2026-67281 (disclosure of root-owned files, including configuration stores).

CERT Poland says attackers have been deploying MikrTrick since at least 2 September, with activity seen from two IP addresses and the creation of an account named “ops.” Shadowserver reported more than 120,000 MikroTik devices exposed to SSH from the Internet during a 24-hour window up to 5 September.

Users are advised to upgrade RouterOS to one of the versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible. The updates also remediate the TLS, file-tampering, and root-file-disclosure issues noted above.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline