MikroTik SSH Chain Hit Routers a Day Before Sept. 3 Patch

Poland's national cybersecurity team, CERT Polska, said on September 5 that attackers were taking full administrative control of MikroTik routers whose SSH service is reachable from public networks, using a two-bug chain it named "MikroTrick." No valid credentials are required.
CERT Polska's advisory describes the chain in two steps. In CVE-2026-67276, RouterOS matches an incoming SSH key against an authorized user's key by type and modulus but skips the exponent; an attacker who knows that user's RSA modulus can present a key with an exponent of one, forge a signature that passes, and get in without the private key. CVE-2026-86060 is an argument-injection flaw in the SSH login path, triggered by usernames that begin with a forbidden character, which lets the attacker alter RouterOS's policy mask and escalate to administrator. The team published six CVEs in total. One of the others, CVE-2026-67277, has RouterOS accept a "related" bandwidth-test connection before the main session has authenticated, which CERT Polska says can leak kernel memory or reboot the device.
The timeline is the sharp edge. MikroTik published fixed builds on September 3 — RouterOS 6.49.21, 7.23.4, 7.24.2 and the development release 7.25beta3 — and its security page calls the release "an important security update," adding that "most configurations are not at risk, but upgrading is highly recommended." CERT Polska dates the attacks it has observed to at least September 2, a day before those builds existed. It links the successful attacks seen so far, including the creation of an account named "ops," to the IP address 82.192.72.4, and separate exploitation attempts to 103.102.31.18.
Scale is the second problem. The Shadowserver Foundation counted roughly 122,500 MikroTik devices with SSH exposed to the internet as of September 5, a figure reported by BleepingComputer. MikroTik hardware is a common choice for small internet providers, businesses and home labs, and a router sits in the path of every connection behind it — which is what separates this from a bug in a single application.
How many of those devices are vulnerable to the full chain is unknown: CERT Polska has not published a figure, and only devices with SSH reachable from the open internet are exposed. Administrators can search for the indicators the team listed — log lines reading "login failure for user -2 ... via ssh" or "user <name> added by ssh:-2@<ip>", and any unfamiliar privileged account such as "ops" — but CERT Polska warns that their absence does not rule out unauthorized activity. Its guidance is to update first, then inspect the device; MikroTik's is to keep SSH off untrusted networks, limiting the port to trusted IPs or reaching the router over a VPN such as WireGuard. CERT Polska adds that compromised devices should be isolated and their logs preserved before any factory reset.
Sources
- CERT Polska — Critical vulnerabilities in MikroTik RouterOS are being actively exploitedPrimary source
- CERT Polska — Podatności w oprogramowaniu MikroTik RouterOS (CVE details)Primary source
- MikroTik — September 2026 vulnerabilityPrimary source
- BleepingComputer — Hackers exploit new MikroTik RouterOS flaws to hijack routersSecondary
Related
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Trending now
- King Charles Convenes AI Leaders in Scotland, Palace Confirms
- Celine Dion Opens 16-Show Paris Run, First Concert in 6 Years
- Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
- Zverev Beats Shelton in 4 Sets for First US Open Title
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
Comments
No comments yet. Be the first.