← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 24, 2026 · 18:16via Security Affairs

AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

Brief

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days.

MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last long. Within days, researchers had reconstructed the whole attack chain from the patch files themselves.

CERT Polska’s Sławomir Rozbicki had reported some of the underlying bugs through coordinated disclosure, and the team expected to publish alongside MikroTik’s release. The vendor shipped early instead. That gap between “patch is out” and “details are public” turned out to be shorter than anyone planned for, and it’s the whole story here.

Read more on Security Affairs→