← Journal
SecurityUpdated 15 September 2026

MikroTrick: critical vulnerability chain in RouterOS already used for hacking

MikroTrick: critical vulnerability chain in RouterOS already used for hacking
Kozuch, CC BY-SA 4.0

The Polish Computer Emergency Response Team CERT Polska has reported six vulnerabilities in the RouterOS operating system used by MikroTik routers. Two of them, combined into a chain called MikroTrick, allow an attacker to gain full administrative access to the device without knowing the password — provided that the SSH service is accessible from the internet.

The most serious vulnerability (CVE-2026-67276, CVSS score 9.2) is related to incomplete validation of public keys during SSH authentication. The system compared not the entire RSA key but only part of it, so knowing the username and key modulus, an attacker could pick another key and log in without the private key. The second vulnerability in the chain (CVE-2026-86060) allowed privilege escalation through a specially crafted username starting with an invalid character. Together, they give full control over the device.

CERT Polska confirmed that the MikroTrick chain is already actively used in real attacks. According to the team, exploitation attempts have been observed since at least September 2, 2026, some originating from IP addresses 82.192.72.4 and 103.102.31.18. Logs on compromised devices may contain characteristic entries, such as SSH login errors for user ‘-2’ or creation of a high-privilege user named ‘ops’. The absence of such traces does not guarantee security, but their presence requires immediate investigation.

Besides the SSH vulnerabilities, CERT Polska identified four more issues: they affect the SSH client, the bandwidth-test service, X.509 certificate processing, and the WebFig interface. One of them (CVE-2026-67277, CVSS 8.8) allowed an unauthenticated user to put bandwidth-test into a state available only after login, leading to data leakage from kernel memory or remote denial of service with device reboot.

Fixes have already been released in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. For the first time in MikroTik’s history, a push notification was sent to users of its mobile app urging them to update. Additionally, the updated versions include a “Flagged” mechanism: upon boot, the system scans the configuration for known signs of unauthorized changes, disables suspicious entries, logs a critical message, and marks the device. Important: such a marker is not proof of compromise by these specific vulnerabilities, and its absence does not guarantee security.

Researchers recommend that administrators update RouterOS immediately and then check the configuration for unknown users, scripts, scheduler tasks, proxy servers, and tunnels. If updating is not yet possible, restrict access to SSH, WWW/WWW-SSL, and bandwidth-test services from external networks and avoid using built-in SSH clients until the patch is installed.

An unusual detail: the vulnerabilities were discovered not manually, but with the help of large language models GPT-5.5-cyber and GPT-5.6-sol within the OpenAI Government and Trust Agency Collaboration program. A CERT Polska researcher used an agent environment to automate the laboratory and systematically search for vulnerabilities — the models helped analyze code and protocols, but each finding was verified on real hardware.

Primary source: cert.pl ↗

← All newsRead XORit on Telegram ↗

We use cookies to make our website convenient and also to collect analytics in Yandex.Metrica. By staying on the site, you give your Consent to personal data processing in the order specified in Personal Data Processing Policy

Request a call
or contact us

Request a call

[contact-form-7 id="188"]

Your request has been successfully
sent

We will contact you shortly,
to discuss cooperation details

An error occurred
while sending the form

Please try again later
or contact us directly: