Hackers Are Seizing MikroTik Edge Routers Without Any Login Using the MikroTrick Chain
CERT Polska confirmed real-world exploitation of the MikroTrick chain against internet-exposed MikroTik RouterOS SSH from at least 2 September 2026, before the 5 September disclosure. Public reporting scores CVE-2026-67276 and CVE-2026-86060 at CVSS 9.2, and patched builds are 6.49.21, 7.23.4, or 7.24.2.

GBHackers (Mayura Kathir, 18 September 2026) says attackers are using a chain dubbed MikroTrick to take full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on 5 September 2026 and confirmed real-world exploitation against SSH-reachable devices.
This is an active exploitation disclosure, not a lab-only write-up. The scope is exposed SSH, not a claim that every MikroTik worldwide is owned. Attacks were observed from at least 2 September, before the public patches.
Public reporting chains CVE-2026-67276, an SSH authentication bypass, and CVE-2026-86060, a session privilege trick via crafted usernames. Both are scored CVSS 9.2. Bishop Fox reproduced a related chain on RouterOS 7.x that starts with CVE-2026-67279 instead of CVE-2026-67276, then uses the same CVE-2026-86060 privilege step. Those two first-stage CVE numbers are not the same write-up.
Cyber Security News (Tushar Subhra Dutta, 18 September 2026) says Bishop Fox later found configuration artifacts consistent with real compromise on internet-facing boxes. One observed technique used a scheduler entry to recreate a privileged account after defenders deleted it. Attacker-added accounts, scripts, and schedulers can survive a reboot even when memory-resident login history does not.
Patched releases include RouterOS 6.49.21, 7.23.4, 7.24.2, or later. The update blocks new exploitation. It does not remove attacker persistence or rotate secrets already visible to a compromised router.
Related login-bypass tape includes Cisco ISE web management already under active exploit and Check Point Security Management servers open to unauthenticated root.
If a RouterOS box has SSH on an untrusted network, upgrade to 6.49.21, 7.23.4, or 7.24.2 today, then hunt schedulers and scripts that recreate admin accounts before you reset, and rotate every password, SSH key, VPN secret, and API credential the router could have seen.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free