securityaffairs.com 6 Sept 2026, 13:46 UTC

MikroTik RouterOS Zero Day Chain Gives Attackers Admin Control

MikroTik RouterOS Zero Day Chain Gives Attackers Admin Control
CyberSIXT Evidence Panel Source marked as original reporting
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MIKROTIK RouterOS is currently being attacked via a zero‑day chain named MikroTrick, which exploits two vulnerabilities that CERT Polska disclosed as part of a broader set of six issues. The active exploitation began by 2 September 2026 and has been validated by a high‑profile analysis from Costin Raiu and CERT Polska. The two CVEs involved are CVE-2026-67276, an SSH authentication bypass, and CVE-2026-86060, an SSH privilege‑escalation flaw.

When combined, these flaws can give an attacker full administrator control of an internet‑exposed RouterOS device with SSH enabled, potentially without the need for the private key if the attacker knows a valid username and the public RSA key.

Evidence of exploitation includes Polish forum logs indicating exploitation attempts on 2 September and CERT Polska confirming successful attacks, including creation of an “ops” account. Observed attacker activity has originated from IPs such as 82.192.72[.]4 and 103.102.31[.]18, with associated dropped files ftpsrv[.]py, launch[.]sh and serve[.]py.

The incident has prompted a patch‑as‑applied response: MikroTik released fixes in versions 7.25beta3, 7.24.2, 7.23.4, 7.23.5 and 6.49.21 on 3 September, but exploitation reportedly began on 2 September; defenders are advised to patch immediately and inspect logs for indicators like an SSH username of -2, or the creation of new users and SSH keys, firewall rule changes, or proxy/tunnel configurations in the system history. The full IOCs include the two CVEs, IPs, and the listed file hashes.

View full article

Article by CyberSIXT