MikroTrick chain gives passwordless admin takeover of MikroTik routers; CISA KEV listing and Canadian advisory AV26-958 add urgency
CERT Polska's MikroTrick chain (CVE-2026-67279 + CVE-2026-86060) lets attackers seize internet-exposed MikroTik RouterOS devices without authentication; exploitation predates the September 3 patches, CISA added CVE-2026-86060 to KEV, and Canada's Cyber Centre…
MikroTrick, reconstructed by CERT Polska, chains two MikroTik RouterOS SSH flaws — CVE-2026-67279, in which an SSH rekey during login skips authentication confirmation and opens a session channel, and CVE-2026-86060, in which an unsanitized username argument lets the attacker supply a fully privileged policy — to give unauthenticated attackers full administrative control of routers with SSH exposed to the internet. Failed logins for user "-2" appeared in logs by September 2, 2026, one day before MikroTik shipped fixes on September 3, 2026 in RouterOS 6.49.21, 7.23.4, and 7.24.2. Observed intrusions created a privileged "ops" admin account and pulled diagnostic files from compromised routers to attacker IP 82.192.72.4; The Hacker News additionally lists 103.102.31.18 as a second attacker IP. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, 2026. Separately, the Canadian Centre for Cyber Security's advisory AV26-958 (September 23, 2026) states RouterOS versions before 7.25beta5 are affected and notes the 7.25beta development build was available as of September 22 — version framing that differs from the September 3 fixed-release list, and it names no CVE and reports no exploitation. CERT Polska cautions that patching does not remove attacker-made changes; administrators who see indicators should reset and rotate credentials. A third flaw, CVE-2026-67276, is not part of the chain. Researchers used the AI models GPT-5.5-cyber and GPT-5.6-sol to help recover the bugs within days of the silent update.
- Chain composition: CVE-2026-67279 (SSH rekey during login skips authentication confirmation and opens a session channel) plus CVE-2026-86060 (unsanitized username argument allows supplying a fully privileged policy, e.g. "-2").
- Impact: unauthenticated full administrative control of MikroTik RouterOS devices with SSH exposed to the internet.
- Exploitation evidence (failed "-2" logins) appeared by September 2, 2026, one day before patches.
- MikroTik patched on September 3, 2026 in RouterOS 6.49.21, 7.23.4, and 7.24.2.
- Canadian Centre for Cyber Security advisory AV26-958 (September 23, 2026) covers RouterOS before 7.25beta5; the 7.25beta development build was available as of September 22 — this version range differs from the fixed-release list, and the…
- CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on September 10, 2026.
Coverage timelineoldest first · each row is one article
- · 3d agoMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
The Hacker News· 86
Attackers chained two MikroTik RouterOS SSH flaws to seize internet-exposed routers without authentication; CISA lists one in KEV.
- · 3d agoMikroTik security advisory (AV26-958)
Canadian Centre for Cyber Security· 38
Canada's Cyber Centre warns MikroTik RouterOS before 7.25beta5 is vulnerable and urges updates.
- · 2d agoAI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
Security Affairs· 86
Vulnerabilities in this storyAll →
- CVE-2026-860609.22%Argument-Injection Flaw in MikroTik RouterOS SSH Login Enables Privilege Escalationpublished · MikroTik RouterOS v6 (Long-term channel) KEV PoC ×3+2 related
| CVE | Vulnerability |
|---|