securityaffairs.com 24 Sept 2026, 18:16 UTC

MikroTik RouterOS Flaws Enabled Passwordless Admin Access via SSH

MikroTik RouterOS Flaws Enabled Passwordless Admin Access via SSH
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

MIKROTIK RouterOS vulnerabilities CVE-2026-67279 and CVE-2026-86060 can be chained to provide unauthenticated access to the administrative console. CERT Polska identified the attack chain, dubbed MikroTrick, after analysing MikroTik’s 3 September 2026 security update and suspicious administrator reports. CVE-2026-67279 allows an unauthenticated SSH client to create a `session` channel, while CVE-2026-86060 enables attacker-controlled input to reach the RouterOS login process.

By sending the username `-2`, an attacker can exploit file-descriptor handling and set the privilege mask to `655358`, representing the fully privileged group. The result is administrator access without a password or SSH key.

CERT Polska said evidence indicates the chain was exploited before the patches were released. Reports from the MikroTik forum, Reddit and direct submissions described failed logins using `-2`, followed by creation of a privileged `ops` account. Several incidents reportedly involved the extraction of diagnostic files. The same source IP, `82.192.72.4`, appeared repeatedly in attack logs, although the article does not establish who controlled it. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue on 10 September, with a three-day remediation deadline.

Researchers used GPT-5.5-cyber, GPT-5.6-sol and locally hosted models alongside an isolated lab containing 40 virtual RouterOS devices across 24 versions. They advised RouterOS operators, particularly those exposing SSH to the internet, to apply MikroTik’s patches and check logs for rejected `-2` login attempts and unexpected `ops` accounts.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline