CERT Polska has warned that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to take control of exposed routers. The vulnerabilities enable a router, if reachable over the internet and running a vulnerable RouterOS build, to be compromised via a two-step exploit known as MikroTrick. Once infiltrated, an attacker can alter DNS settings, redirect or capture traffic, create remote-access tunnels, adjust firewall rules, or use the device as a foothold to target other network hosts. The warning emphasises that an edge device at the network boundary is particularly risky.
Two of the six disclosed vulnerabilities form the MikroTrick chain. CVE-2026-67276 is an SSH authentication-bypass flaw in how RSA public keys are handled, allowing entry without a password. CVE-2026-86060 is a privilege-escalation flaw tied to a specially crafted username in the SSH login process, enabling an attacker to elevate privileges to administrator. CERT Polska notes that the patched RouterOS packages are already public, and the community has reconstructed aspects of the flaws from available analyses.
To stay safe, MikroTik router owners should install the latest RouterOS security update and remove public access to the router’s management services, ensuring SSH is not reachable from untrusted networks and limiting remote administration to known IP addresses. Administrators should also audit full configurations after any suspected compromise, using the device’s Flagged status as a preliminary indicator. The article stresses that a strong password alone cannot avert these authentication-bypass vulnerabilities.