News

MikroTik RouterOS takeover chain hits devices with exposed SSH

CERT Polska confirmed active exploitation of the MikroTrick chain (CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2) against RouterOS devices with internet-reachable SSH. Successful attacks from 82.192.72.4 have created a privileged user named ops since at least 2 September. Patched builds are 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.

MikroTik RouterOS takeover chain hits devices with exposed SSH

CERT Polska published a coordinated disclosure on 5 September 2026 covering six RouterOS vulnerabilities. Two of them form a chain the team named MikroTrick: unauthenticated full admin control when SSH is reachable from the internet.

This is a national CERT active-exploitation advisory, paired with MikroTik's 4 September forum security update (normis). It is not a CISA Known Exploited Vulnerabilities listing, and it is not an unpatched zero-day. Fixes are already in 7.25beta3, 7.24.2, 7.23.4, and 6.49.21.

CVE-2026-67276 (CVSS 9.2) is an SSH public-key check that compared RSA type and modulus but not the full key and exponent. An attacker who knows a username and that modulus can craft a key and log in without the private key. CVE-2026-86060 (CVSS 9.2) lets a username that begins with a disallowed character, logged as -2, reach a legacy helper and escalate to full admin. A third bug, CVE-2026-67277 (CVSS 8.8), is bandwidth-test memory disclosure and denial of service.

CERT says exploitation is confirmed against devices whose SSH service is on a public network, not against every home RouterOS box sitting behind the default firewall. MikroTik told home users that default configs are not at immediate risk and still told everyone to upgrade. In the same thread, normis said many years of versions are affected and that the fix exists only from the named releases on.

The extra forensic detail is the account and the source IP. Successful attacks, including creation of a privileged user named ops, have come from 82.192.72.4 since at least 2 September. CERT also logged exploit attempts from 103.102.31.18. Look for login failure for user -2 from <ip> via ssh and user <name> added by ssh:-2@<ip>.

Patched builds stop the observed attacks. After the upgrade, RouterOS can set a Flagged device-mode marker when it sees known compromise fingerprints. Absence of Flagged is not proof the box is clean. Isolate, collect logs, factory-reset, and rebuild from a trusted config if Flagged, ops, or those login lines show up.

CERT used GPT-5.5-cyber and GPT-5.6-sol inside a supervised GTAC lab to speed hypothesis search. Every finding was then verified on real RouterOS by researchers, with negative controls and clean-state repeats. That is human-supervised lab work, not a model that found the bugs on its own.

Internet-facing management planes keep drawing the same treatment, from a Cisco Nexus 9000 Silicon One root RCE to SonicWall SMA 1000 zero-days under active attack and a Chrome V8 bug already exploited in the wild. CERT's lab access sat under OpenAI's government program, adjacent to the company's Daybreak frontline-defender pledge.

If SSH on a RouterOS box is reachable from an untrusted network, upgrade today to 7.24.2, 7.23.4, 6.49.21, or 7.25beta3, then hunt for the ops account and the -2 SSH login lines. Until the patch lands, restrict SSH, WWW, and bandwidth-test to trusted nets, and keep built-in SSH clients off untrusted hosts from an unpatched device.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free