CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.
Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.