MikroTik RouterOS MikroTrick: Unauth SSH Chain Hijacks Devices

By George Bailey   Published: 09/17/26   Updated: 09/17/26   2 min read

Internet-exposed MikroTik SSH just became a takeover story again. CERT.pl’s MikroTrick chain combines authentication bypass and privilege escalation so an unauthenticated attacker can own RouterOS — and two of the CVEs are already on CISA’s KEV list.

If SSH, WebFig, or bandwidth-test is reachable from untrusted networks, patch and lock those services down before the weekend scans finish the job for you.

What happened

MikroTik published a September 2026 security update covering multiple RouterOS flaws reported with CERT.pl. The headline chain:

Fixed builds: 6.49.21 (long-term), 7.23.4, 7.24.2, and 7.25 beta 3. CISA added CVE-2026-67277 and CVE-2026-86060 to KEV on September 10, 2026 (federal due September 13). Exploitation of the SSH chain has been reported against devices with SSH exposed to the internet.

Why it matters

Edge routers with open management ports are botnet, pivot, and traffic-hijack candy. A full-admin RouterOS foothold means DNS, VPN, firewall rules, and upstream routes are attacker-editable.

RouterOS can mark compromised devices as Flagged in logs — but only if you look. Patch without config review is how persistence survives the upgrade.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.