INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
MikroTik RouterOS Flaws Hijack Routers Without Password Authentication
| 2026-09-07 10:55 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A series of critical vulnerabilities have been discovered in MikroTik routers, allowing attackers to take control without a password. The first tracked vulnerability, CVE-2026-67276, is an SSH authentication-bypass flaw that enables unauthorized access, while the second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process. These vulnerabilities collectively form the "MikroTrick" chain of compromise, which can be exploited to gain full control over vulnerable devices. MikroTik routers are sold worldwide, including in the US, and attackers are actively exploiting these flaws to seize control of exposed routers. To mitigate this risk, users should install the latest RouterOS security update as soon as possible and remove public access to management services, limiting remote administration to known IP addresses.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-86060, CVE-2026-67277 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
6e95f7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
972b47••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6dca83••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
se•••••.py
la•••••.sh
ft•••••.py
82.192.•••.•••
103.102.•••.•••
hxxp://••••••••••••••••••••
ce•••••.pl
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060
CVE-2026-67277CVE-2026-67277
CVE-2026-67276CVE-2026-67276
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
as early as September 2
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 6.49.21 before the release of patches on September 3.
Click on any entity below to view its context and source!
infrastructure
7.24.2
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
infrastructure
7.23.4
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
infrastructure
6.49.21
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
organisation
7.25beta3
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
Sept 2
Threat actors are actively exploiting a MikroTik RouterOS SSH zero-day vulnerability, known as the "MikroTrick chain," which began on September 2.
Click on any entity below to view its context and source!
organisation
MikroTrick
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Pierluigi Paganini
September 06, 2026
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2.
September 3
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 6.49.21 before the company released fixes on September 3.
Click on any entity below to view its context and source!
target_region
Poland
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
attribution
CERT
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
infrastructure
7.24.2
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
infrastructure
7.23.4
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
infrastructure
6.49.21
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
attribution
RouterOS 7.25beta3
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
organisation
7.25beta3
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
September 4
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 7.23.5 to gain unauthorized control of affected routers on September 4.
Click on any entity below to view its context and source!
infrastructure
7.24.2
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
infrastructure
7.23.4
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
infrastructure
7.23.5
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
September 5
The ShadowServer Foundation reported that as of September 5, approximately 122,500 MikroTik devices had an exposed SSH interface.
Click on any entity below to view its context and source!
organisation
The ShadowServer Foundation
As of September 5, there were
122,500 MikroTik devices
with an exposed SSH interface, according to data provided by The ShadowServer Foundation.
infrastructure
122,500 MikroTik devices
As of September 5, there were
122,500 MikroTik devices
with an exposed SSH interface, according to data provided by The ShadowServer Foundation.
September 5, 2026
Threat actors actively exploited previously disclosed vulnerabilities in MikroTik RouterOS, prompting CERT Polska to issue an advisory on September 5, 2026.
Click on any entity below to view its context and source!
attribution
CERT Polska
The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active exploitation on September 5, 2026, the same day CERT Polska issued its advisory titled “
Critical vulnerabilities in MikroTik RouterOS are being actively exploited.
attribution
MikroTik RouterOS
The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active exploitation on September 5, 2026, the same day CERT Polska issued its advisory titled “
Critical vulnerabilities in MikroTik RouterOS are being actively exploited.
September 06, 2026
Threat actors are actively exploiting a MikroTik RouterOS SSH zero-day, known as the "MikroTrick chain," which has been ongoing since September 2.
Click on any entity below to view its context and source!
organisation
MikroTrick
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Pierluigi Paganini
September 06, 2026
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2.
2026/09/07
Threat actors used a chain of two recently disclosed vulnerabilities in MikroTik RouterOS to take control of devices with SSH services exposed to the internet.
Click on any entity below to view its context and source!
organisation
MikroTik RouterOS
Hackers exploit new MikroTik RouterOS flaws to hijack routers.
organisation
MikroTrick
The Polish agency dubbed the exploit chain “MikroTrick,” and warned that it is now actively exploited in the wild.
Two of the
six disclosed vulnerabilities
form the chain of compromise known as MikroTrick.
data_breach
2 September
A Polish security forum
contained
logs showing September 2 exploitation attempts, and CERT Polska confirmed successful attacks including the creation of an “ops” account dating to at least September 2.
organisation
RSA
The first, tracked as
CVE-2026-67276
, is an SSH authentication-bypass flaw in the handling of RSA public keys.
One of the security issues, tracked as CVE-2026-67276, is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys.
organisation
RouterOS verifies RSA
“
CVE-2026-67276 flaw stems from how RouterOS verifies RSA public keys.
organisation
MikroTik
MikroTik router flaws allow takeover without a password.
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”.
organisation
SSH
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.
Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise.
organisation
RouterOS
The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.
“In recent days we have been observing attacks against RouterOS devices accessible from the internet.
organisation
Secure Shell
SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.
organisation
IP
If remote administration is necessary, limit access to known IP addresses.
A second IP, 103.102.31[.]18, has also been associated with the campaign.
organisation
WWW
For those unable to apply the updates immediately, one recommendation is to restrict or disable externally accessible SSH, WWW/WWW-SSL, and bandwidth-test services, and avoid the built-in SSH clients and outbound TLS connections over untrusted networks.
organisation
TLS
For those unable to apply the updates immediately, one recommendation is to restrict or disable externally accessible SSH, WWW/WWW-SSL, and bandwidth-test services, and avoid the built-in SSH clients and outbound TLS connections over untrusted networks.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
infrastructure
82.192.72
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
The full list of IOCs from Raiu’s analysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py).
infrastructure
1.16.1
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
organisation
82.192.72[.]4
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
organisation
MIPS
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
infrastructure
103.102.31
The full list of IOCs from Raiu’s analysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py).
organisation
VirusTotal
Three of the four hosted files have no VirusTotal detections as of writing.
organisation
Astra
Astra
refused on safety grounds and suggested he apply for cyber verification.
organisation
Sol, Daybreak Blue
The other three (Sol, Daybreak Blue, and GLM-5.3) were willing to help but none could complete a working implementation.
organisation
GitHub
That gap gives defenders an estimated one to two days before a working proof of concept appears publicly on GitHub, which is better than nothing but not by much given that exploitation is already happening at scale from a single IP.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, MikroTik)
2026/09/08
Threat actors exploited vulnerabilities in MikroTik RouterOS to gain unauthorized access, potentially leading to unplanned takeover of affected devices.
Tactical Metrics
Metrics
infrastructure
7.24.2
Software Version
Click for context!
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
Metrics
infrastructure
7.23.4
Software Version
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
Metrics
infrastructure
6.49.21
Software Version
MikroTik
fixed the vulnerabilities
in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes.
“MikroTik has released fixes in versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, however, it would appear that exploitation began as early as September 2, making it a 0day.”
Metrics
infrastructure
122,500
Mikrotik Devices
As of September 5, there were
122,500 MikroTik devices
with an exposed SSH interface, according to data provided by The ShadowServer Foundation.
Metrics
infrastructure
82.192.72
Software Version
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
The full list of IOCs from Raiu’s analysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py).
Metrics
infrastructure
1.16.1
Software Version
Most of the attacks observed so far originated from 82.192.72[.]4, a Leaseweb IP that was hosting a busybox binary (a MIPS build from 2010, identical to the official BusyBox 1.16.1 precompiled binary), alongside three other files: ftpsrv.py, launch.sh, and serve.py.
Metrics
infrastructure
7.23.5
Software Version
Patched versions are 7.25beta3, 7.24.2, 7.23.4, 7.23.5 (released September 4), and
Metrics
infrastructure
103.102.31
Software Version
The full list of IOCs from Raiu’s analysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py).
Metrics
data_breach
2
September
A Polish security forum
contained
logs showing September 2 exploitation attempts, and CERT Polska confirmed successful attacks including the creation of an “ops” account dating to at least September 2.
Intelligence Sources
Security Affairs
2026-09-06
Malware Bytes
2026-09-08
MikroTik router flaws allow takeover without a password
Malware Bytes
BleepingComputer
2026-09-07
Hackers exploit new MikroTik RouterOS flaws to hijack routers
BleepingComputer
AlienVault OTX
2026-09-07
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-08T06:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
MikroTik RouterOS
entity
10x
timeline
Temporal Reference
2026/09/08
date
7x
attribution
Attributing Entity
CERT Polska
authority
7x
infrastructure
Software Version
7.24.2
version
3x
vulnerability
Exploited CVE
CVE-2026-67276
cve
2x
target region
Target Country
Poland
country
Contextual Telemetry
Context Block
6 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
infrastructure
Mikrotik Devices
122,500
mikrotik devices
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
vulnerability
CVSS Score
9
score
data breach
September
2
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.