Your MikroTik Router Can Look Clean After Attackers Take It Over
A MikroTik router can keep forwarding traffic, show reassuring green lights and still belong to someone else.
CERT Polska has confirmed active attacks that chain two newly assigned RouterOS vulnerabilities. The first bypasses SSH authentication without the victim’s private key. The second can turn that foothold into a full-administrator account. Together, they give an attacker durable control of the device while leaving plenty of room to make the configuration look ordinary.
The campaign has been active since at least 2 September 2026. Latvia’s national incident-response team has already identified 12 compromised devices and thousands of exposed routers. The urgent action is clear: update RouterOS. The harder part begins afterwards, because installing a fixed build does not remove an account, script, tunnel or configuration change planted before the patch.
Four RouterOS Flaws Now Have Evidence of Exploitation
Update, 29 September 2026: CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities catalogue on 25 September, with a 28 September remediation deadline for covered US federal civilian agencies. CISA says the unauthenticated SSH workflow flaw can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
That does not establish that this chain was used in CERT Polska’s original MikroTrick campaign, which involved CVE-2026-67276 and CVE-2026-86060. CISA does not identify the campaign, victims, actor or scale behind the newer entry. The count of four combines CERT Polska’s original two findings with CISA’s separate exploitation entries for CVE-2026-67277 and CVE-2026-67279; it is not a claim that four flaws appear in KEV or were used in one campaign.
CISA records ransomware use as Unknown and forensic triage as No for CVE-2026-67279. Neither field establishes that ransomware was absent or that non-federal operators can safely skip investigation.
Update, 11 September 2026: CISA added CVE-2026-86060 and CVE-2026-67277 to KEV on 10 September. Covered US federal civilian agencies had until 13 September 2026 to apply the required remediation.
The change corrects one part of this article’s original status table. CVE-2026-67277, which can disclose kernel memory and force a denial of service through the RouterOS bandwidth-test service, must now be treated as exploited. CISA has not published the victims, attack sequence or evidence behind the catalogue decision, and it has not said that this vulnerability forms part of the MikroTrick chain documented by CERT Polska.
At the time of the 11 September update, that distinction left three exploitation statements in the same bulletin. CERT Polska linked CVE-2026-67276 and CVE-2026-86060 in the observed SSH-to-administrator chain. CISA separately confirmed exploitation of CVE-2026-67277. The 29 September update above adds the fourth flaw without retrospectively merging the campaigns.
CISA’s catalogue marks forensic triage as required for CVE-2026-86060 and not required for CVE-2026-67277 under its federal directive workflow. That field should not be read as proof that non-federal operators can safely skip investigation. A router exposed before the fixed release may still need log, account and configuration review, especially when the same device was reachable through SSH, WebFig or another administrative service.
The 11 September update originally recommended 6.49.21, 7.23.4 and 7.24.2. CERT Polska later clarified that the first 7.x fix for CVE-2026-67278 was incomplete. Current 7.x fleet guidance is 7.23.6 or later on Long-term, or 7.24.3 or later on Stable. For affected 6.x devices, use 6.49.21 or later. Review exposed services and unexplained restarts as well as the accounts and configuration. Patching does not explain activity before the update.
MikroTrick turns a public SSH key into a login
The attack chain begins with CVE-2026-67276, an SSH authentication bypass scored 9.2. An attacker needs a valid RouterOS username, the public modulus of an RSA key associated with that account and network access to the router’s SSH service. The corresponding private key is not required.
That distinction matters. This is not a blind login with no knowledge of the target, but a public key is not supposed to function as a secret. The weakness collapses the security boundary that makes public-key authentication useful in the first place.
Once connected, attackers can use CVE-2026-86060, another 9.2-rated flaw, to manipulate privileges through a crafted username. CERT Polska says the two vulnerabilities have been exploited together to create a new user with full administrative rights.
The researchers named the chain MikroTrick. Their work also has an unusual research detail: CERT Polska says GPT-5.5-cyber and GPT-5.6-sol assisted its supervised laboratory analysis. The models did not make the exploitation claim on their own. Human researchers reproduced the flaws, connected them to incident evidence and published the operational findings.
The bulletin contains six vulnerabilities, not two
The documented MikroTrick campaign used CVE-2026-67276 and CVE-2026-86060. CISA separately confirms exploitation of CVE-2026-67277 and CVE-2026-67279. It describes a possible chain between the latter and CVE-2026-86060, without attributing it to CERT Polska’s original campaign. Evaluate the complete release rather than treating one observed chain as the entire exposure.
| Vulnerability | What it can do | Prerequisite | Status |
|---|---|---|---|
| CVE-2026-67276 | Bypass SSH authentication using a username and RSA public modulus | Reachable SSH service and target account information | Confirmed exploitation in a chain |
| CVE-2026-86060 | Manipulate privileges and create a full-administrator account | An authenticated path, supplied by the first flaw in observed attacks | Confirmed exploitation in a chain |
| CVE-2026-67277 | Leak memory through bandwidth-test traffic and force a kernel restart | Network access to the affected service | Confirmed exploitation, added to CISA KEV on 10 September 2026; CISA has not linked it to the MikroTrick chain |
| CVE-2026-67278 | Use malformed RSA signatures to impersonate outbound TLS endpoints under attacker-controlled conditions | Ability to redirect or control the destination path | No confirmed exploitation |
| CVE-2026-67279 | Create, overwrite or reconstruct files through the SSH rekey workflow | Network access and a vulnerable SSH workflow | Confirmed exploitation, added to CISA KEV on 25 September 2026. The entry describes possible chaining with CVE-2026-86060 but does not connect it to the original CERT Polska campaign. |
| CVE-2026-67281 | Read root-owned files and configuration credentials through WebFig | Access to the vulnerable /jsproxy path |
No confirmed exploitation |
The last four issues create opportunities for disruption, outbound TLS impersonation, file manipulation and disclosure of device configuration. CISA confirms exploitation of CVE-2026-67277 and CVE-2026-67279. The primary sources reviewed on 29 September did not confirm malicious exploitation of CVE-2026-67278 or CVE-2026-67281.
A public proof of concept shortens the path to reproduction
An independent researcher published a laboratory proof of concept for CVE-2026-67276 on 6 September. The repository demonstrates the bypass against RouterOS 7.23.3 and shows the same attempt being rejected by 7.23.4.
The repository is not endorsed by MikroTik or either national CERT. It is nevertheless a material change in defender urgency because it gives other researchers and attackers a concrete reproduction path. Public proof-of-concept availability should not be confused with the separate evidence of malicious exploitation, which CERT Polska had already confirmed for the two-flaw chain.
Fixed versions close the vulnerabilities, not the incident
The minimum version depends on both branch and vulnerability. CERT Polska says the first 7.x fix for CVE-2026-67278 was incomplete. The table below distinguishes that exception from the other five fixes.
| Vulnerability | Affected range | Minimum fixed version |
|---|---|---|
| CVE-2026-67276 | 7.9 before 7.23.4; 7.24 before 7.24.2 | 7.23.4 Long-term or 7.24.2 Stable |
| CVE-2026-67277 | 6.0.0 before 6.49.21; 7.0.0 before 7.23.4; 7.24 before 7.24.2 | 6.49.21, 7.23.4 Long-term or 7.24.2 Stable |
| CVE-2026-67278 | 7.0.0 before 7.23.6; 7.24 before 7.24.3 | 7.23.6 Long-term or 7.24.3 Stable |
| CVE-2026-67279 | 6.0.0 before 6.49.21; 7.0.0 before 7.23.4; 7.24 before 7.24.2 | 6.49.21, 7.23.4 Long-term or 7.24.2 Stable |
| CVE-2026-67281 | 7.20 before 7.23.4; 7.24 before 7.24.2 | 7.23.4 Long-term or 7.24.2 Stable |
| CVE-2026-86060 | 6.0.0 before 6.49.21; 7.0.0 before 7.23.4; 7.24 before 7.24.2 | 6.49.21, 7.23.4 Long-term or 7.24.2 Stable |
For a 7.x fleet, the practical current floor across all six flaws is 7.23.6 or later on Long-term, or 7.24.3 or later on Stable. RouterOS 6.x is not listed as affected by CVE-2026-67276, CVE-2026-67278 or CVE-2026-67281; use 6.49.21 or later for the other three listed flaws. Prefer an appropriate supported Stable or Long-term release over moving to a beta solely for this bulletin.
Routers that were reachable before the upgrade require an incident check. CERT Polska’s automated Flagged scan looks for selected traces, but the team explicitly warns that a clean result does not prove a device was never compromised.
The logs can reveal an account created from nowhere
CERT Polska published several high-value indicators. Successful activity was associated with 82.192.72.4, while attempts were observed from 103.102.31.18. Administrators should also search RouterOS logs for entries such as login failure for user -2 and user <name> added by ssh:-2@....
The campaign created a high-privilege account named ops in documented cases. That name is useful for hunting, but defenders should not reduce the investigation to one username. An attacker able to create an administrator can choose another name, alter existing accounts, add scripts or schedules, change firewall rules and establish tunnels that blend into legitimate remote management.
What MikroTik administrators should do now
- Use the current fixed floor for the branch. Install 7.23.6 or later on Long-term or 7.24.3 or later on Stable to include the complete fix for CVE-2026-67278. For affected 6.x devices, install 6.49.21 or later.
- Restrict SSH, WebFig and administrative services to trusted management networks. Do not leave them exposed to the public internet.
- Review local users, groups, SSH keys, scripts, schedulers, firewall rules, DNS settings, proxies, VPNs and tunnels for unauthorised changes.
- Search logs for the published IP addresses, the
-2user traces and administrator creation over SSH. - Do not treat a negative automated scan as proof of safety.
- If compromise is suspected, isolate the router, preserve its configuration and logs, then rebuild it from a trusted baseline or factory reset it before restoring carefully reviewed settings.
- Rotate router credentials, VPN secrets, keys and any other credentials that the device could read or intercept.
- Verify the version that is actually running after the upgrade and confirm that the device restarted on the fixed build.
The rebuild advice is deliberately stronger than a simple password change. Full router control places an attacker at a privileged network boundary. Traffic redirection, DNS manipulation, credential capture and persistent remote access may survive long after the vulnerable login path has been closed.
A working network is not the same as a trustworthy network
Routers are easy to neglect precisely because a compromise does not have to interrupt service. An attacker who wants persistence benefits from keeping the lights green and the packets moving.
MikroTrick is therefore more than a patch story. It is a reminder that infrastructure can remain operational after its control plane has failed. The organisations that recover cleanly will be the ones that patch quickly, then ask the uncomfortable second question: what changed while the door was open?
MikroTrick questions
Is the MikroTik attack unauthenticated?
The observed chain bypasses normal SSH authentication, but the attacker still needs a valid username, an RSA public modulus associated with the account and access to the SSH service. The private key is not required.
Has MikroTrick been exploited in real attacks?
Yes. CERT Polska says attackers have chained CVE-2026-67276 and CVE-2026-86060 in active attacks since at least 2 September 2026.
Is CVE-2026-67277 part of MikroTrick?
Not on the evidence currently public. CISA confirms that CVE-2026-67277 is exploited, but it does not identify the campaign or connect the activity to the two-flaw MikroTrick chain described by CERT Polska.
Is CVE-2026-67279 part of MikroTrick?
CISA confirms exploitation and says it can be chained with CVE-2026-86060. CERT Polska’s original observed campaign instead used CVE-2026-67276 with CVE-2026-86060. Public evidence does not establish that the newer CISA-described chain was used in that campaign.
Does patching prove the router is clean?
No. The update closes the vulnerabilities but does not remove changes made before installation. Exposed devices require account, configuration, log and persistence review.
Sources and further reading
- CERT Polska: vulnerabilities in MikroTik RouterOS actively exploited, published 5 September 2026. No publication time was provided.
- CERT Polska: technical analysis of six RouterOS vulnerabilities, published 5 September 2026. No publication time was provided.
- MikroTik September 2026 security bulletin, published 3 September 2026. No publication time was provided.
- CERT.LV: increased attempts to compromise MikroTik routers, published 4 September and updated 6 September 2026. No times were provided.
- Independent MikroTrick laboratory proof of concept, repository created 6 September 2026 at 14:10:51 Europe/Madrid.
- BleepingComputer: attackers exploit RouterOS flaws to hijack routers, published 7 September 2026 at 06:32 as displayed. The page does not label its timezone.
- CISA official GitHub KEV feed, catalogue version 2026.09.27, released 27 September 2026 at 21:30:35 UTC. The CVE-2026-86060 and CVE-2026-67277 entries were added 10 September; CVE-2026-67279 was added 25 September. Their respective due dates of 13 and 28 September apply to covered US federal civilian agencies, not universally to private operators.


