Critical MikroTik RouterOS Flaws Allowed Full Takeover Without Credentials
CERT Polska disclosed a two-vulnerability exploit chain called MikroTrick in September 2026, targeting MikroTik RouterOS devices reachable via SSH over the internet. The first flaw, CVE-2026-67276, is an SSH public-key authentication bypass caused by a logic error that ignores the RSA exponent during key verification, allowing unauthenticated access. The second, CVE-2026-86060, is a privilege escalation triggered by a malformed username, granting full administrative control once an attacker is authenticated. Both vulnerabilities carry critical CVSS scores between 9.2 and 9.8, and active exploitation was recorded from September 2, 2026 — one day before MikroTik released patched versions across its 6.x and 7.x release trains. Unpatched devices exposed to the internet should be treated as potentially compromised, and administrators are advised to upgrade immediately or restrict SSH access to trusted addresses as an interim measure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in