INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

MikroTik RouterOS Flaws Hijack Routers Without Password Authentication

| 2026-09-07 10:55 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A series of critical vulnerabilities have been discovered in MikroTik routers, allowing attackers to take control without a password. The first tracked vulnerability, CVE-2026-67276, is an SSH authentication-bypass flaw that enables unauthorized access, while the second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process. These vulnerabilities collectively form the "MikroTrick" chain of compromise, which can be exploited to gain full control over vulnerable devices. MikroTik routers are sold worldwide, including in the US, and attackers are actively exploiting these flaws to seize control of exposed routers. To mitigate this risk, users should install the latest RouterOS security update as soon as possible and remove public access to management services, limiting remote administration to known IP addresses.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-86060, CVE-2026-67277 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

6e95f7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
972b47••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6dca83••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
se•••••.py
la•••••.sh
ft•••••.py
82.192.•••.•••
103.102.•••.•••
hxxp://••••••••••••••••••••
ce•••••.pl
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060 CVE-2026-67277CVE-2026-67277 CVE-2026-67276CVE-2026-67276
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎as early as September 2
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 6.49.21 before the release of patches on September 3.
infrastructure 7.24.2
infrastructure 7.23.4
infrastructure 6.49.21
organisation 7.25beta3
‎Sept 2
Threat actors are actively exploiting a MikroTik RouterOS SSH zero-day vulnerability, known as the "MikroTrick chain," which began on September 2.
organisation MikroTrick
‎September 3
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 6.49.21 before the company released fixes on September 3.
target_region Poland
attribution CERT
infrastructure 7.24.2
infrastructure 7.23.4
infrastructure 6.49.21
attribution RouterOS 7.25beta3
organisation 7.25beta3
‎September 4
Threat actors exploited previously unknown vulnerabilities in MikroTik RouterOS versions 7.24.2, 7.23.4, and 7.23.5 to gain unauthorized control of affected routers on September 4.
infrastructure 7.24.2
infrastructure 7.23.4
infrastructure 7.23.5
‎September 5
The ShadowServer Foundation reported that as of September 5, approximately 122,500 MikroTik devices had an exposed SSH interface.
organisation The ShadowServer Foundation
infrastructure 122,500 MikroTik devices
‎September 5, 2026
Threat actors actively exploited previously disclosed vulnerabilities in MikroTik RouterOS, prompting CERT Polska to issue an advisory on September 5, 2026.
attribution CERT Polska
attribution MikroTik RouterOS
‎September 06, 2026
Threat actors are actively exploiting a MikroTik RouterOS SSH zero-day, known as the "MikroTrick chain," which has been ongoing since September 2.
organisation MikroTrick
‎2026/09/07
Threat actors used a chain of two recently disclosed vulnerabilities in MikroTik RouterOS to take control of devices with SSH services exposed to the internet.
organisation MikroTik RouterOS
organisation MikroTrick
data_breach 2 September
organisation RSA
organisation RouterOS verifies RSA
organisation MikroTik
organisation SSH
organisation RouterOS
organisation Secure Shell
organisation IP
organisation WWW
organisation TLS
organisation The Blue Report 2026
infrastructure 82.192.72
infrastructure 1.16.1
organisation 82.192.72[.]4
organisation MIPS
infrastructure 103.102.31
organisation VirusTotal
organisation Astra
organisation Sol, Daybreak Blue
organisation GitHub
organisation SecurityAffairs
‎2026/09/08
Threat actors exploited vulnerabilities in MikroTik RouterOS to gain unauthorized access, potentially leading to unplanned takeover of affected devices.
Tactical Metrics
Metrics
infrastructure
‎7.24.2
Software Version
Metrics
infrastructure
‎7.23.4
Software Version
Metrics
infrastructure
‎6.49.21
Software Version
Metrics
infrastructure
122,500
Mikrotik Devices
Metrics
infrastructure
‎82.192.72
Software Version
Metrics
infrastructure
‎1.16.1
Software Version
Metrics
infrastructure
‎7.23.5
Software Version
Metrics
infrastructure
‎103.102.31
Software Version
Metrics
data_breach
2
September
Intelligence Sources