MikroTik RouterOS Exploit Chain Leaves Detectable Log Trails, Devices Still at Risk
Two vulnerabilities, CVE-2026-67279 and CVE-2026-86060, form the 'MikroTrick' exploit chain targeting MikroTik RouterOS, documented by CERT Polska and patched in September 2026 releases covering versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. The two-stage attack abuses SSH rekeying and a username-parsing flaw to gain full administrative access without valid credentials. Defenders can identify compromise attempts by looking for failed login entries for the username '-2' followed by the creation of an unauthorised 'ops' account in SSH logs. Observed attacks went beyond access, with attackers exporting device diagnostic files to external addresses, suggesting data collection as an additional goal. Security researchers warn that patching alone is insufficient — any internet-facing device that was unpatched during the active exploitation window should be audited, with credentials, certificates, and tunnel keys rotated if compromise indicators are found.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in