MicroTik Routers Under Attack in New Campaign
Labeled "MikroTrick" by researchers at CERT Polska who discovered and disclosed six vulnerabilities in the software, the campaign targets devices with SSH services reachable from the public internet

Labeled "MikroTrick" by researchers at CERT Polska who discovered and disclosed six vulnerabilities in the software, the campaign targets devices with SSH services reachable from the public internet
September 6, 2026 | 3 min read

Threat actors are actively exploiting a critical vulnerability chain in MikroTik RouterOS that enables full administrative takeover of internet-facing devices without requiring any authentication.
Labeled "MikroTrick" by researchers at CERT Polska who discovered and disclosed six vulnerabilities in the software, the campaign targets devices with SSH services reachable from the public internet. This high-impact exploitation, which has been observed in the wild since September 2, forced a significant security response from MikroTik and requires immediate administrative action by teams running any vulnerable devices.
Originally, researchers thought the exploit activity began after the patches were released on Sept. 3, but it now seems that attackers targeted the bugs the day before. MicroTik, a Latvian vendor that makes a wide range of networking gear, published details of the
“In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks. It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately,” the CERT Polska advisory says.
The attack vector relies on chaining two primary vulnerabilities to bypass standard access controls. The initial entry point is CVE-2026-67276, an SSH authentication bypass vulnerability. RouterOS fails to correctly verify the full RSA public key during authentication; specifically, it verifies the key type and modulus but neglects to compare the exponent. An attacker who is aware of a valid username and the public modulus of a legitimate user’s key can craft a fake key that satisfies this incomplete validation, allowing them to initiate an SSH session without possessing the corresponding private key. Once this initial bypass is successful, the attackers leverage CVE-2026-86060, a privilege escalation flaw rooted in improper argument handling within the SSH login process. By using a crafted username beginning with a prohibited character, such as the -2 identifier, attackers can inject arguments into the system’s command-line utilities. This manipulation alters the trusted RouterOS policy mask, elevating the unauthorized session to full administrative privileges.
“Technical indicators and information obtained by CERT Polska through internal channels pointed to the possibility of RouterOS vulnerabilities being actively exploited in real-world attacks conducted in recent days. We now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control of devices whose SSH service is accessible from public networks. According to the information we have, updating to the latest version prevents these attacks,” CERT Polska said.
Compromised systems have been observed featuring new, highly privileged accounts—most notably a user named "ops"—often associated with traces such as ssh:-2@. This activity is indicative of a manual, hands-on exploitation playbook where attackers gain initial access, establish persistent administrative accounts, and perform subsequent configuration modifications. The relative simplicity of this SSH-based entry point allows attackers to bypass traditional credential-based security, making the threat particularly dangerous for administrators who rely on direct remote access without restrictive firewall policies.
MikroTik has released urgent security updates across all channels, including versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, which effectively patch the vulnerabilities. Administrators should update their devices immediately and perform a thorough audit of their current configurations for unknown scripts, scheduled tasks, or unauthorized user accounts.
Researchers at the Shadowserver Foundation found more than 122,000 MicroTik devices with SSH enabled exposed to the internet in its scans on Sept. 6.
Because the vulnerability facilitates complete system compromise, mere patching may not be sufficient if the device has already been successfully attacked; affected organizations should inspect system logs for signs of intrusion, such as unexpected user creation or unauthorized configuration changes, and consider full restoration from known-good backups. Until updates can be applied, experts strongly emphasize restricting access to management ports to trusted networks or mandating VPN-based access, as the current exploitation landscape demonstrates that internet-exposed management services remain a primary, high-value target for both automated scanning and targeted manual attacks.
September 6, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.