· via dev.to (home feed)
MikroTrick: Two Critical RouterOS Flaws Exploited to Take Over MikroTik Routers Without a Password
CERT Polska disclosed two critical MikroTik RouterOS flaws, already exploited as the MikroTrick chain, that hand attackers admin access to routers with exposed SSH, no password or key required.

Passwordless takeover of exposed routers
MikroTik routers whose SSH management service is reachable from the internet are being compromised through a chain of two vulnerabilities that requires no password and no stolen key. According to a dev.to analysis of the disclosure, CERT Polska published an advisory on September 5, 2026 covering six RouterOS vulnerabilities, two of them rated critical, and confirmed that attackers were already using that pair to seize devices. The chain has been named MikroTrick, and CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 10, giving US federal agencies a September 13 remediation deadline.
How the chain works
The first flaw, CVE-2026-67276, is a missing-authentication weakness (CWE-306). As described in the public analysis, RouterOS verifies RSA public keys incompletely during SSH login: the modulus is compared but the exponent is never checked. Anyone who knows a valid username and the modulus of the key registered to it can craft a key that passes verification and log in.
The second, CVE-2026-86060, is an argument-delimiter injection flaw (CWE-88). Having bypassed authentication, the attacker submits a username constructed to smuggle extra arguments into the SSH login process, which lifts the session to full administrator privileges.
Neither bug alone yields complete control of a device. Chained, they hand an unauthenticated attacker who can reach SSH administrator-level access. Several trackers cited in the write-up score each flaw at 9.2 on the CVSS scale.
Zero-day timing and scale
Attackers moved before the advisory existed. CERT Polska's telemetry, as cited by dev.to, records hostile activity starting September 2, 2026 — one day before MikroTik shipped patches on September 3 and three days before public disclosure, which makes this a zero-day exploitation event. MikroTik released RouterOS 6.49.21, 7.23.4, 7.24.2 and 7.25beta3, followed by 7.23.5 on September 4, and for the first time pushed a warning to users through its official mobile app.
Public figures referenced in the write-up count more than 122,000 affected devices, though that number describes RouterOS instances exposed and potentially vulnerable rather than confirmed breaches, and the two should not be conflated.
Indicators and the new Flagged check
Reported indicators of compromise include SSH login attempts under the invalid username "-2", the creation of an unapproved high-privilege account named "ops", and attacker source addresses 82.192.72.4 (hosted at Leaseweb) and 103.102.31.18.
Patched RouterOS builds also introduce a "Flagged" mechanism: at boot the device runs a self-check against known tampering artifacts and marks itself when it finds any. A device reporting as flagged should be handled as compromised.
What operators should do
- Upgrade to RouterOS 6.49.21, 7.23.4, 7.24.2 or later; the patched releases block the observed attacks and add the Flagged self-check.
- Keep SSH, WebFig and the bandwidth-test service off the public internet, restricted to a trusted management network.
- Search logs for SSH logins using the username "-2" and audit local user accounts for unauthorized entries such as "ops".
- Check whether the device reports itself as Flagged.
- Treat any sign of compromise as total: once an attacker has held administrator access, changing the password is not enough. Isolate the device, review configuration changes, and rebuild it before returning it to service.
Why it matters
RouterOS powers edge routers and wireless access points in small and medium businesses, at ISPs and in home offices — machines that run around the clock, sit at the perimeter of the network, and often go years without an update. An attacker with full control of such a box can watch passing traffic, rewrite routing and firewall rules, and repurpose the hardware as a relay or tunnel for further operations.
The detail worth remembering is the public-key bypass itself. Key-based SSH login is widely treated as inherently stronger than password login, but when verification ignores part of the key, that assumption fails without any credential being stolen. MikroTrick is also a reminder that two individually incomplete flaws can compose into a complete takeover, and that an exposed management port is often all an attacker needs.
- #mikrotik
- #routeros
- #security
- #ssh
- #vulnerabilities