TTO-2026-0907-105 · September 7, 2026 Active ExploitationCritical

MikroTik RouterOS SSH Chain Exploited Before Patch Ships — 300,000 Devices Remain Exposed

mikrotik.comCVE-2026-67276 CVSS 9.2CVE-2026-86060 CVSS 9.2SSH auth bypassPrivilege escalationPatched Sep 3

Summary

Attackers are actively exploiting a chained pair of critical SSH vulnerabilities in MikroTik RouterOS, dubbed MikroTrick by CERT Polska, to seize full administrative control of internet-exposed routers without valid credentials. The first flaw, CVE-2026-67276 (CVSS 9.2), bypasses SSH authentication by exploiting incomplete RSA public key validation. The second, CVE-2026-86060 (CVSS 9.2), escalates the resulting session to full administrative privileges through a crafted username. MikroTik patched both flaws on September 3, 2026, but exploitation was already underway from at least September 2 — giving the campaign zero-day characteristics. Shodan scans indicate approximately 300,000 RouterOS devices remain unpatched and internet-exposed.

Timeline

DateEvent
Sep 2, 2026First confirmed exploitation observed — unauthorized "ops" account created via SSH from IP 82.192.72.4
Sep 3, 2026MikroTik releases patched RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21
Sep 5, 2026CERT Polska publishes full technical advisory covering CVE-2026-67276, CVE-2026-86060, and a third flaw CVE-2026-67277
Sep 7, 2026~300,000 vulnerable RouterOS devices remain internet-exposed per Shodan; public PoC circulating

What Happened

CVE-2026-67276 exists because RouterOS validates SSH public key logins by checking only the key type and modulus, skipping the exponent. An attacker who knows a valid username and the public modulus of that user's RSA key can supply a crafted key with an exponent of one, fake a valid signature, and open an SSH session as that user without ever possessing the legitimate private key. CVE-2026-86060 then escalates that session: a specially crafted username manipulates RouterOS's SSH session-handling to return a session with full administrative privileges. Together, the two flaws allow unauthenticated full takeover of any RouterOS device with SSH exposed to the internet.

A third vulnerability, CVE-2026-67277, affects RouterOS's bandwidth-test service and allows unauthenticated attackers to leak kernel memory or remotely crash the device, but this flaw has not been confirmed exploited in the same campaign. CERT Polska credited AI-assisted research in identifying the flaw chain. MikroTik introduced compromise-detection features alongside the patches. Administrators should treat any unexplained highly privileged account named "ops" as a confirmed indicator of compromise requiring full device reimaging.

Domain Intelligence

mikrotik.com — 60.94

Score sits in the low-trust range. One threat intelligence source has flagged mikrotik.com but the observation has not yet been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026