Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

MikroTik Patches Critical Flaws Chained to Hack Routers

Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.

Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited.

The exploited flaws, dubbed MikroTrick, allow attackers to bypass authentication and take over devices, CERT Poland warns.

In a scarce advisory, MikroTik warns of the identified security defects, recommends immediate patching, and directs users to CERT Poland’s advisory for additional information.

“This is an important security update. Most configurations are not at risk,” MikroTik says. It also recommends blocking SSH access from untrusted sources, noting that compromised devices will have a “Flagged” entry in the log section.

CERT Poland, meanwhile, says it has received confirmation that two of the resolved vulnerabilities have been chained together to compromise devices.

“We now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control of devices whose SSH service is accessible from public networks. According to the information we have, updating to the latest version prevents these attacks,” CERT Poland notes.

Advertisement. Scroll to continue reading.

It highlights three vulnerabilities: CVE-2026-67276 (CVSS score of 9.2), an SSH authentication bypass bug; CVE-2026-86060 (CVSS score of 9.2), an SSH session privilege manipulation issue; and CVE-2026-67277 (CVSS score of 8.8), a memory disclosure and denial-of-service weakness.

CERT Poland says hackers have been chaining the MikroTrick bugs since at least September 2, creating an account named ‘ops’. The attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18.

“The presence of any of these artifacts indicates an attempt to exploit the vulnerabilities and must be investigated immediately; at the same time, the absence of the traces mentioned above does not rule out unauthorized activity,” CERT Poland notes.

Users are advised to update their MikroTik routers to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible.

The updates also resolve CVE-2026-67278 (enables TLS server impersonation), CVE-2026-67279 (allows unauthenticated attackers to tamper with files, including configuration files), and CVE-2026-67281 (allows attackers to disclose root-owned files, including configuration stores).

The Shadowserver Foundation found more than 120,000 MikroTik devices with SSH accessible from the internet during a 24-hour scan window on September 5.

Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX

Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Related: Malicious Virtualizor Update Served via BGP Hijacking

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.