BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MikroTik SSH flaws chained for full router takeover

Critical MikroTik RouterOS SSH vulnerability chain allows unauthenticated full admin control over routers; patch now

  • A chain of two SSH vulnerabilities—CVE-2026-67279 and CVE-2026-86060—allows unauthenticated attackers to gain full administrative control over exposed MikroTik RouterOS devices.
  • Active exploitation began before patches were released; fixes are available in RouterOS 6.49.21, 7.23.4, and 7.24.2.
  • Attackers create a privileged ‘ops’ account and exfiltrate configuration data; indicators include username ‘-2’ in logs and IPs 82.192.72.4 and 103.102.31.18.
  • Administrators should patch immediately and check for signs of compromise, including flagged device status and unknown files or users.

Security researchers have uncovered a critical vulnerability chain in MikroTik RouterOS that lets unauthenticated attackers take full administrative control of internet-exposed routers without any password or SSH key. The chain, dubbed “MikroTrick” by CERT Polska, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug (CVE-2026-86060) in the login process.

- Advertisement -

According to the technical analysis published by CERT Polska, the first vulnerability forces the SSH server to skip authentication during a key renegotiation, while the second abuses a login program to accept a crafted username “-2” that grants full administrative privileges. The attack sequence has been observed since at least September 2, one day before MikroTik shipped patches in RouterOS versions 6.49.21, 7.23.4, and 7.24.2.

Indicators of compromise include failed login logs for user “-2”, creation of a privileged account named “ops”, and connections to attacker-controlled IPs such as 82.192.72.4 and 103.102.31.18. CerT Polska found evidence of configuration data being transferred to attacker infrastructure after exploitation, and a diagnostic report on the MikroTik forum confirms the attack sequence on a device.

MikroTik states that its default home configuration does not expose SSH to the internet, but administrators who have modified firewall rules face higher risk. After patching, administrators should check the Flagged status by running /system/device-mode/print (see the device-mode documentation) and search for unknown scripts, scheduler entries, or unexpected .rif files.

If compromise is suspected, CERT Polska recommends isolating the device, preserving logs, factory resetting it, and rebuilding from a trusted configuration—do not restore backups from an infected system. All passwords and keys should be changed. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, independently confirming active exploitation. Note that a separate SSH flaw, CVE-2026-67276, is not part of this chain and requires prior knowledge of a user’s public key to exploit.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Suit: OpenAI let contractors read ChatGPT chats sans consent

Two California ChatGPT users filed a proposed class action against OpenAI this month in...

Revolut hit by second data breach in September

UK bank Revolut disclosed a second customer data breach this month after former broker...

Only 4 digital asset treasury firms trade above NAV: report.

Only four of the 20 largest digital asset treasury (DAT) companies trade above a...

Placeholder domain third-party.com now serves ClickFix malware

The long-trusted documentation placeholder domain "third-partycom" has been weaponized to serve a ClickFix malware...

Microsoft Stock Hits $500, Analyst Sees Rally to $575

Microsoft stock (NASDAQ: MSFT) opened at $500 on Thursday, a key resistance level it...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading