Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ssh-auth-bypass (1 article)Clear

Exploited MikroTik flaw chain gives full router control over exposed SSH

Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.

Check
Update RouterOS to a fixed release now, take SSH off the internet by restricting it to a management network or VPN, and hunt exposed devices for a rogue user named dash-two.
Affected
Internet-exposed MikroTik RouterOS devices with SSH enabled (CVE-2026-67276); an unauthenticated attacker can bypass SSH authentication and escalate to full administrator, and about 300,000 devices are still exposed and being targeted.
Fix
Patch RouterOS, keep SSH and management interfaces off the public internet, rotate all router and downstream credentials and SSH keys, disable unused services, and rebuild any device confirmed compromised.