← All stories
● Covered by 3 sources · 3 reportsMedium impact2 negative1 neutral

Attackers Exploit MikroTik Routers via Internet-Exposed SSH for Unauthorized Access

🔄 Updated 24d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attackers exploit MikroTik routers via exposed SSH services.
  • Vulnerability allows full administrative control without authentication.
  • MikroTik released RouterOS security updates to fix the issue.
  • CERT Polska recommends immediate updates and configuration checks.
  • The vulnerabilities are CVE-2026-67276 and CVE-2026-86060.
  • CVE-2026-67276 is an SSH authentication bypass due to incomplete RSA public key validation.
  • CVE-2026-86060 is an SSH privilege escalation flaw from improper handling of usernames.
  • Poland's CERT discovered the vulnerabilities with GPT-5.5-cyber and GPT-5.6-sol.
  • The exploit chain is dubbed "MikroTrick" by Poland's CERT.
  • MikroTik added a compromise-detection mechanism to updates.
  • MikroTik released patches for six vulnerabilities in RouterOS.
  • MikroTik recommends blocking SSH access from untrusted sources.
  • MikroTik notes compromised devices will have a 'Flagged' entry in the log section.

MikroTik Routers Under Attack

CERT Polska issued a warning on September 5 regarding active exploitation of MikroTik routers. Attackers are targeting routers with Secure Shell (SSH) remote-access services exposed to the internet, enabling them to gain full administrative control without requiring authentication. Successful attacks have been observed since at least September 2.

Security Updates Released

MikroTik has released security updates for its RouterOS, listing fixed versions that prevent the observed attacks. CERT Polska strongly recommends immediate installation of these updates. Following the update, users should check their router configurations for any unauthorized changes that may have occurred.

Mitigation and Recovery Steps

Until updates can be installed, CERT Polska advises turning off exposed services like SSH, WWW/WWW-SSL, and bandwidth-test, or restricting access to trusted management networks. They also recommend against initiating TLS connections or using RouterOS's built-in SSH clients from unpatched devices. If compromise is suspected, CERT recommends isolating the router, preserving logs and configuration, restoring factory settings, and rebuilding with a verified configuration.

Checking for Compromise

MikroTik's RouterOS can flag devices when suspicious configurations are detected during startup, disabling affected entries and restricting functions. After updating, users should check logs and run '/system/device-mode/print' to inspect the device status. Signs of compromise include unknown users, scripts, unrecognized changes, unexpected highly privileged operations accounts, and account-creation logs containing 'ssh:-2@'.

Updates

🕒 2026-09-08 · new reporting from SecurityWeek
  • MikroTik released patches for six vulnerabilities in RouterOS.
  • MikroTik recommends blocking SSH access from untrusted sources.
  • MikroTik notes compromised devices will have a 'Flagged' entry in the log section.
🕒 2026-09-07 · new reporting from BleepingComputer
  • The vulnerabilities are CVE-2026-67276 and CVE-2026-86060.
  • CVE-2026-67276 is an SSH authentication bypass due to incomplete RSA public key validation.
  • CVE-2026-86060 is an SSH privilege escalation flaw from improper handling of usernames.
  • Poland's CERT discovered the vulnerabilities with GPT-5.5-cyber and GPT-5.6-sol.
  • The exploit chain is dubbed "MikroTrick" by Poland's CERT.
  • MikroTik added a compromise-detection mechanism to updates.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

MikroTik released patches for six vulnerabilities in RouterOS, including two actively exploited flaws dubbed "MikroTrick" that allow authentication bypass and device takeover. CERT Poland confirmed these two vulnerabilities have been chained together to compromise devices, urging users to update immediately.

Hackers are exploiting two recently disclosed vulnerabilities in MikroTik RouterOS, CVE-2026-67276 and CVE-2026-86060, to gain full control of routers with exposed SSH services. These flaws, dubbed "MikroTrick" by Poland's CERT, allow attackers to bypass SSH authentication and escalate privileges, leading to active exploitation in the wild. MikroTik has released updates to patch these issues and added a compromise-detection mechanism.

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.