Hackers exploit new MikroTik RouterOS flaws to hijack routers

MikroTik Routers Under Attack: Hackers Exploit Critical Flaws for Full Control

A serious security threat is unfolding as hackers have started exploiting a chain of two recently discovered vulnerabilities in MikroTik routers, allowing them to take control of devices with SSH services exposed to the internet. Poland’s CERT agency has dubbed this exploit chain “MikroTrick,” and warned that it’s now being actively used by attackers.

The security issues at play are two critical vulnerabilities tracked as CVE-2026-67276 and CVE-2026-86060, both affecting MikroTik RouterOS. The first flaw is an SSH authentication bypass vulnerability caused by incomplete validation of RSA public keys. An attacker who knows a username and the public modulus of that user’s key can exploit it by crafting a different key and logging in without the legitimate private key. The second issue is an SSH privilege escalation flaw due to improper handling of specially crafted usernames, allowing hackers to manipulate the SSH session and obtain full administrative privileges.

Both vulnerabilities were discovered with the help of advanced AI tools and received a critical severity rating from Poland’s CERT agency. In its advisory, the vendor notes that not all configurations are affected, but did not disclose any details to give users time to apply security updates. The latest RouterOS versions – 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3 – include fixes for the vulnerabilities.

The good news is that MikroTik has fixed the issues in its latest updates, but users are still at risk if they haven’t applied the patches yet. Poland’s CERT notes that not all routers are affected, but it’s essential to apply the security updates as soon as possible to prevent exploitation. For those unable to do so immediately, restricting or disabling externally accessible SSH services is a temporary solution.

According to data from The ShadowServer Foundation, there were over 122,500 MikroTik devices with an exposed SSH interface as of September 5. While we don’t know the exact number of devices vulnerable to the exploit chain, it’s clear that this threat has significant potential for widespread impact.

In light of these events, it’s essential to be proactive and take steps to protect your network from this threat. If you suspect compromise, follow Poland’s CERT advice: isolate the router, preserve logs and configuration, then factory-reset the device and rebuild it from a trusted configuration while rotating passwords, keys, and other secrets. By staying informed and taking prompt action, we can minimize the damage and keep our networks secure.


Source: Bleeping Computer — 2026-09-07