ACT TONIGHT

MikroTik RouterOS: unauthenticated SSH takeover chain ("MikroTrick") exploited since Sept 2

Incident / Filed 3 Sep 2026 / Updated 28 Sep 2026 / CVE-2026-67279, CVE-2026-86060, CVE-2026-67276, CVE-2026-67277

routermikrotik

What: Attackers are taking full admin on MikroTik routers over SSH with no password and no key. The chain ("MikroTrick", named by CERT Polska): CVE-2026-67279 lets an unauthenticated client skip SSH auth by asking for a rekey mid-login. CVE-2026-86060 then feeds the username -2 to the login helper and gets full admin rights. Attacks started 2026-09-02, one day before MikroTik shipped fixes. Both chain CVEs are in CISA KEV. The same release also fixes CVE-2026-67276, where the SSH RSA public-key check ignores the exponent, and CVE-2026-67277, an unauthenticated bandwidth-test (btest) kernel memory leak and crash (also in KEV). Seen after break-in: a new full-admin user ops, plus scripts, scheduler jobs, proxies and tunnels, and file transfers to attacker hosts that look like config theft.

Who it hits: A MikroTik (hAP, RB, CCR, CRS, CHR) on RouterOS below 7.24.2 / 7.23.4 / 6.49.21 where SSH (port 22, or wherever you moved it) is reachable from the internet. That includes a VPS running CHR, and a "temporary" WAN rule allowing SSH that never got removed. MikroTik says the default config doesn't expose SSH on WAN. Scans on 2026-09-05 still found about 122,500 devices with SSH open to the internet. Only the SSH users are exposed to the full chain. A btest server (port 2000) open to the internet is exposed to the leak and the crash.

Check if you're affected:

# From a LAN box: installed version (vulnerable if below 7.24.2, 7.23.4 on long-term, 6.49.21 on v6)
ssh admin@192.168.88.1 '/system resource print' | grep -i version
# From OUTSIDE your network (phone hotspot, VPS): does SSH answer on your WAN IP?
nc -vz -w 5 YOUR_PUBLIC_IP 22

Do this:

  1. Tonight: shut SSH off to the internet. In the RouterOS terminal: /ip service set ssh address=192.168.88.0/24 (use your LAN or VPN subnet), or /ip service disable ssh if you don't use it. Do the same for www, www-ssl and winbox. Then /tool bandwidth-server set enabled=no.

  2. Upgrade: /system package update check-for-updates then /system package update install. You want 7.24.2 or newer on stable, 7.23.4 on long-term, or 6.49.21 on v6. Then /system routerboard upgrade and reboot again so the firmware matches.

  3. Look for signs you were hit: /user print (look for ops or any user you don't know), /log print where message~"-2" (look for login failure for user -2 or added by ssh:-2@), /system script print, /system scheduler print, /ip proxy print, /interface print (look for tunnels you didn't make).

  4. Confirm the fix: /system resource print shows the fixed version, and the nc check from outside times out.

  5. Remote management from now on should go over WireGuard or Tailscale, not an open port.

If you were already hit: Pull the WAN cable. Save /export and the logs for evidence, then netinstall or factory-reset to a fixed version. Rebuild the config by hand; don't restore the backup. Change every password, and rotate every key and WireGuard/VPN secret the router held. It was your gateway, so treat LAN traffic in that window as seen.

Why this level: It answers yes on all five rubric questions: SSH is exposed on WAN on six-figure numbers of devices, three CVEs are in KEV with confirmed attacks, MikroTik is a home-lab router staple, owning the gateway means owning the LAN, and no credentials are needed. It is also an unauthenticated takeover under active exploitation, which triggers the act-tonight override.

Sources

How severity is decided. Source file: incidents/2026-09-03-mikrotik-routeros-mikrotrick-ssh.md.