Threat Intelligence

Two Chained MikroTik Flaws Let Attackers Bypass Login Entirely: Patch Now

The Hacker News · 24 Sept 2026
Key Takeaway If you run MikroTik routers, update to RouterOS 6.49.21, 7.23.4, or 7.24.2 immediately and disable SSH access from the public internet unless it is strictly necessary.

CERT Polska has published details of a vulnerability chain, dubbed MikroTrick, that allows attackers to seize complete control of Internet-exposed MikroTik routers without needing a password, SSH key, or any completed login. The chain combines a flaw in the SSH authentication process (CVE-2026-67279) with a separate bug in how RouterOS handles login commands (CVE-2026-86060). The first flaw lets an attacker trick the router into skipping the authentication check entirely by starting a key renegotiation mid-login. The second flaw then lets the attacker supply a crafted username that the router misinterprets as a system instruction, tricking it into granting a fully privileged administrative session.

Attack activity exploiting this chain has been traced back to at least 2 September, a day before MikroTik released fixes in RouterOS versions 6.49.21, 7.23.4, and 7.24.2. CERT Polska had earlier warned that routers with SSH exposed to the public internet were being compromised, but this new analysis is the first to explain exactly which flaws were involved and how they work together.

Because the attack requires no valid credentials at all, any unpatched router with SSH reachable from the internet is at risk of full takeover, potentially allowing attackers to reconfigure networks, intercept traffic, or use the device as a launch point for further attacks.

MikroTik vulnerability router security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.