⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

September 23, 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key Swati KhandelwalSep 23, 2026Vulnerability / Network Security Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. As previously reported, CERT Polska warned on September 5 that attackers were using RouterOS flaws to take control of devices whose SSH service was reachable from public networks. That warning confirmed the…

CVEs: CVE-2026-67279, CVE-2026-86060, CVE-2026-67276