MikroTik SSH Rekeying and Username Flaws Chain Into Unauthenticated RouterOS Admin Access
Brief
Attackers can combine two MikroTik RouterOS vulnerabilities to gain administrator-level access to exposed routers without a password.
Security researchers at Bishop Fox reproduced the attack chain and found artifacts on real devices that suggest attackers exploited the flaws before public fixes became available.
The issue is especially serious because routers handle traffic between internal networks and the internet.
A compromised MikroTik device could allow attackers to monitor traffic, steal credentials, maintain access, or move deeper into connected networks.
CERT Polska disclosed six actively exploited RouterOS flaws on September 5, 2026. Two of them, tracked as CVE-2026-67279 and CVE-2026-86060, can be chained in an attack known as “MikroTrick.” MikroTik released fixes for all six issues.
