Hackers are actively exploiting two newly disclosed security flaws in MikroTik RouterOS to take control of routers that have SSH services exposed to the internet. The attacks can allow hackers to gain full administrative access to affected devices without needing the legitimate user password. The two vulnerabilities work together as an attack chain known as “MikroTrick,” which was identified by Poland’s CERT agency. CERT Polska has confirmed that attackers are already using this method against RouterOS devices accessible from public networks.

The first vulnerability, tracked as CVE-2026-67276, is an SSH authentication bypass caused by incomplete validation of RSA public keys. An attacker who knows a username and the public modulus linked to that account can create another key and use it to log in without having the real private key. The second flaw, CVE-2026-86060, is a privilege escalation vulnerability caused by the improper handling of specially created usernames. By exploiting it, attackers can manipulate an SSH session and obtain full administrative privileges on the router.

CERT Polska said it began seeing attacks against internet-accessible RouterOS devices in recent days and confirmed that the attackers were using the two vulnerabilities together. The agency also identified another security issue, CVE-2026-67277, affecting the RouterOS bandwidth-test service. This flaw can allow an unauthenticated attacker to leak kernel memory or remotely crash and restart a vulnerable router. CERT Polska discovered and coordinated the disclosure of six RouterOS vulnerabilities affecting several components, including SSH, bandwidth testing, certificate handling and WebFig.

MikroTik released security updates on September 3 that address the vulnerabilities, with fixes included in RouterOS versions 7.25beta3, 7.24.2, 7.23.4 and 6.49.21. The company has not provided detailed technical information about the affected configurations, giving users time to install the security updates. The updates also introduce a compromise-detection feature that checks for known signs of unauthorized configuration changes when the router starts. If malicious entries are found, the mechanism can disable them and record a critical warning in the system logs.

CERT Polska has warned that the absence of a compromise marker does not guarantee that a router is safe because attackers may have removed or changed evidence of their activity. Signs that administrators should check include unusual SSH log entries, the presence of a highly privileged account named “ops,” and connections involving the IP addresses 82.192.72.4 and 103.102.31.18. If a router is suspected of being compromised, CERT recommends isolating it and preserving its logs and configuration information. The recommended recovery process includes a factory reset, rebuilding the router from a trusted configuration, and changing passwords, keys and other secrets.

Users who cannot immediately install the security updates should reduce exposure by restricting or disabling internet-accessible SSH, WWW, WWW-SSL and bandwidth-test services. Administrators are also advised to avoid using built-in SSH clients and outbound TLS connections over untrusted networks until the device can be properly secured. Data from The Shadowserver Foundation showed that around 122,500 MikroTik devices had an exposed SSH interface as of September 5, although the exact number vulnerable to the MikroTrick attack is not known. With active exploitation already confirmed, MikroTik users should update affected routers as soon as possible and check their devices for signs of unauthorized access.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news