CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6831

As cited

Copy frozen at (site build).

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six MikroTik RouterOS flaws, including a two-vulnerability chain called MikroTrick that enables unauthenticated attackers to gain full administrative control over internet-facing devices. The most critical issues are CVE-2026-67276 (SSH authentication bypass, CVSS 9.2), CVE-2026-86060 (privilege escalation via crafted username, CVSS 9.2), and CVE-2026-67277 (bandwidth-test service denial of service and memory disclosure, CVSS 8.8). MikroTik has released patched versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and administrators must update immediately and audit configurations for unauthorized accounts and modifications.

Why it matters: Network administrators and service providers using MikroTik RouterOS must patch immediately, as attacks exploiting these flaws have been documented since September 2, 2026, targeting devices with exposed SSH services.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six vulnerabilities in MikroTik RouterOS, including a two-flaw chain called MikroTrick that bypasses SSH authentication and grants full administrative control to internet-facing devices. The most critical flaws are CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2, along with CVE-2026-67277 rated 8.8. MikroTik has released patched versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, with the company sending push notifications to app users urging immediate updates.

Why it matters: Organizations operating MikroTik routers with publicly exposed SSH must patch immediately, as attackers are actively creating privileged accounts on vulnerable devices; administrators should also check logs for unauthorized users and configuration changes that may indicate prior compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed six vulnerabilities in MikroTik RouterOS are under active exploitation, with a two-flaw chain called MikroTrick enabling unauthenticated attackers to gain full administrative access to internet-exposed devices. The most critical flaws include CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2, affecting SSH authentication and privilege escalation, plus CVE-2026-67277 at CVSS 8.8 targeting the bandwidth-test service. MikroTik has released patched versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, with CERT Polska urging immediate updates and configuration audits for signs of unauthorized changes.

Why it matters: Network administrators managing MikroTik routers, especially those with SSH exposed publicly, face immediate risk of complete device compromise and should patch now and inspect logs and configs for evidence of exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six vulnerabilities in MikroTik RouterOS, including a two-flaw chain called MikroTrick that permits unauthenticated attackers to gain full administrative control of internet-facing devices. The most critical flaws are CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2, which bypass SSH authentication and enable privilege escalation respectively. MikroTik released patches in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 9, 2026, and administrators must update immediately while checking for unauthorized accounts, scripts, and configuration changes.

Why it matters: Network administrators operating internet-accessible MikroTik RouterOS devices need to patch immediately; attackers have actively exploited these flaws since at least September 2, 2026, and could obtain full control of routers that form critical network infrastructure for ISPs, enterprises, and data centers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six MikroTik RouterOS flaws, including a two-flaw chain called MikroTrick that bypasses SSH authentication and grants full administrative control to unauthenticated attackers on internet-exposed devices since at least September 2, 2026. The most critical issues are CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2, affecting SSH key verification and username handling respectively, along with CVE-2026-67277 (CVSS 8.8) in the bandwidth-test service. MikroTik released patches in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and administrators must update immediately and audit devices for unauthorized accounts, scripts, and configuration changes.

Why it matters: Network administrators operating internet-facing MikroTik routers face immediate risk of full device compromise and must patch or restrict SSH access today; enterprises and ISPs using RouterOS in critical infrastructure should prioritize this update as a severity 1 incident.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six MikroTik RouterOS flaws, with two vulnerabilities (CVE-2026-67276 and CVE-2026-86060) forming a chain called MikroTrick that enables unauthenticated attackers to gain full administrative control of internet-exposed devices. Attacks have occurred since at least September 2, 2026, targeting devices with publicly accessible SSH services and creating unauthorized admin accounts. MikroTik has issued patched versions (7.25beta3, 7.24.2, 7.23.4, and 6.49.21), and administrators should update immediately while checking logs and configurations for signs of compromise.

Why it matters: Network administrators running exposed MikroTik RouterOS devices must patch urgently to prevent complete device compromise; ISPs, enterprises, and data centers relying on MikroTik infrastructure face immediate risk from active exploitation of the MikroTrick chain.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed that six vulnerabilities in MikroTik RouterOS are being actively exploited, with two flaws forming a chain called 'MikroTrick' that enables unauthenticated attackers to gain full administrative access to internet-exposed devices. The most critical issues are an SSH authentication bypass (CVE-2026-67276, CVSS 9.2) and a privilege escalation flaw (CVE-2026-86060, CVSS 9.2), both of which have been observed in real attacks since September 2. MikroTik has released patched versions and added an automated detection mechanism that flags compromised devices during startup.

Why it matters: Network administrators running MikroTik RouterOS with exposed SSH services face immediate risk of complete device compromise and should patch to versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 immediately and audit their devices for unauthorized accounts or configuration changes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CERT Polska alerts MikroTik RouterOS vulnerabilities actively being exploited in ‘MikroTrick’ attack chain

CERT Polska confirmed active exploitation of six vulnerabilities in MikroTik RouterOS, with a two-flaw combination called MikroTrick enabling attackers to gain full administrative access to devices with publicly exposed SSH services. The most critical flaws are CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2, which allow authentication bypass and privilege escalation. MikroTik has released patched versions and implemented a detection mechanism that flags suspected compromises at startup, though the absence of a flag does not guarantee safety.

Why it matters: Network administrators operating MikroTik RouterOS devices with internet-facing SSH must patch immediately to prevent unauthorized takeover of routers that may control critical infrastructure, ISP networks, or enterprise connectivity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary