Summary
Attackers are actively exploiting a chained pair of critical SSH vulnerabilities in MikroTik RouterOS, dubbed MikroTrick by CERT Polska, to seize full administrative control of internet-exposed routers without valid credentials. The first flaw, CVE-2026-67276 (CVSS 9.2), bypasses SSH authentication by exploiting incomplete RSA public key validation. The second, CVE-2026-86060 (CVSS 9.2), escalates the resulting session to full administrative privileges through a crafted username. MikroTik patched both flaws on September 3, 2026, but exploitation was already underway from at least September 2 — giving the campaign zero-day characteristics. Shodan scans indicate approximately 300,000 RouterOS devices remain unpatched and internet-exposed.
Timeline
| Date | Event |
|---|---|
| Sep 2, 2026 | First confirmed exploitation observed — unauthorized "ops" account created via SSH from IP 82.192.72.4 |
| Sep 3, 2026 | MikroTik releases patched RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 |
| Sep 5, 2026 | CERT Polska publishes full technical advisory covering CVE-2026-67276, CVE-2026-86060, and a third flaw CVE-2026-67277 |
| Sep 7, 2026 | ~300,000 vulnerable RouterOS devices remain internet-exposed per Shodan; public PoC circulating |
What Happened
CVE-2026-67276 exists because RouterOS validates SSH public key logins by checking only the key type and modulus, skipping the exponent. An attacker who knows a valid username and the public modulus of that user's RSA key can supply a crafted key with an exponent of one, fake a valid signature, and open an SSH session as that user without ever possessing the legitimate private key. CVE-2026-86060 then escalates that session: a specially crafted username manipulates RouterOS's SSH session-handling to return a session with full administrative privileges. Together, the two flaws allow unauthenticated full takeover of any RouterOS device with SSH exposed to the internet.
A third vulnerability, CVE-2026-67277, affects RouterOS's bandwidth-test service and allows unauthenticated attackers to leak kernel memory or remotely crash the device, but this flaw has not been confirmed exploited in the same campaign. CERT Polska credited AI-assisted research in identifying the flaw chain. MikroTik introduced compromise-detection features alongside the patches. Administrators should treat any unexplained highly privileged account named "ops" as a confirmed indicator of compromise requiring full device reimaging.
Domain Intelligence
mikrotik.com — 60.94
Score sits in the low-trust range. One threat intelligence source has flagged mikrotik.com but the observation has not yet been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.
The Trust Observatory · thetrustobservatory.com · September 7, 2026