← Back to feed
Vulnerabilities & PatchesEmerging2 sourcesSep 8, 2026 · 09:49via Malwarebytes Labs

MikroTik router flaws allow takeover without a password

Brief

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network.

Read more on Malwarebytes Labs

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Malwarebytes LabsPrimary··trust 1.28

MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.

Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276 , is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060 , is a privilege-escalation flaw involving a specially crafted username in the SSH login process.

Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.

SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.

CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix.

How to stay safe

MikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik . The update option should be available under Check for updates .

Read more →
Malware.news··trust 0.88

MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.

Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276 , is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060 , is a privilege-escalation flaw involving a specially crafted username in the SSH login process.

Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.

SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.

CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix.

Read more →