MikroTik RouterOS: unauthenticated SSH takeover chain ("MikroTrick") exploited since Sept 2
Incident / Filed 3 Sep 2026 / Updated 28 Sep 2026 / CVE-2026-67279, CVE-2026-86060, CVE-2026-67276, CVE-2026-67277
What: Attackers are taking full admin on MikroTik routers over SSH with no password and
no key. The chain ("MikroTrick", named by CERT Polska): CVE-2026-67279 lets an unauthenticated
client skip SSH auth by asking for a rekey mid-login. CVE-2026-86060 then feeds the username
-2 to the login helper and gets full admin rights. Attacks started 2026-09-02, one day
before MikroTik shipped fixes. Both chain CVEs are in CISA KEV. The same release also
fixes CVE-2026-67276, where the SSH RSA public-key check ignores the exponent, and
CVE-2026-67277, an unauthenticated bandwidth-test (btest) kernel memory leak and crash (also in KEV).
Seen after break-in: a new full-admin user ops, plus scripts, scheduler jobs, proxies and
tunnels, and file transfers to attacker hosts that look like config theft.
Who it hits: A MikroTik (hAP, RB, CCR, CRS, CHR) on RouterOS below 7.24.2 / 7.23.4 / 6.49.21 where SSH (port 22, or wherever you moved it) is reachable from the internet. That includes a VPS running CHR, and a "temporary" WAN rule allowing SSH that never got removed. MikroTik says the default config doesn't expose SSH on WAN. Scans on 2026-09-05 still found about 122,500 devices with SSH open to the internet. Only the SSH users are exposed to the full chain. A btest server (port 2000) open to the internet is exposed to the leak and the crash.
Check if you're affected:
# From a LAN box: installed version (vulnerable if below 7.24.2, 7.23.4 on long-term, 6.49.21 on v6)
ssh admin@192.168.88.1 '/system resource print' | grep -i version
# From OUTSIDE your network (phone hotspot, VPS): does SSH answer on your WAN IP?
nc -vz -w 5 YOUR_PUBLIC_IP 22
Do this:
-
Tonight: shut SSH off to the internet. In the RouterOS terminal:
/ip service set ssh address=192.168.88.0/24(use your LAN or VPN subnet), or/ip service disable sshif you don't use it. Do the same forwww,www-sslandwinbox. Then/tool bandwidth-server set enabled=no. -
Upgrade:
/system package update check-for-updatesthen/system package update install. You want 7.24.2 or newer on stable, 7.23.4 on long-term, or 6.49.21 on v6. Then/system routerboard upgradeand reboot again so the firmware matches. -
Look for signs you were hit:
/user print(look foropsor any user you don't know),/log print where message~"-2"(look forlogin failure for user -2oradded by ssh:-2@),/system script print,/system scheduler print,/ip proxy print,/interface print(look for tunnels you didn't make). -
Confirm the fix:
/system resource printshows the fixed version, and thenccheck from outside times out. -
Remote management from now on should go over WireGuard or Tailscale, not an open port.
If you were already hit: Pull the WAN cable. Save /export and the logs for evidence, then
netinstall or factory-reset to a fixed version. Rebuild the config by hand; don't restore the
backup. Change every password, and rotate every key and WireGuard/VPN secret the router held.
It was your gateway, so treat LAN traffic in that window as seen.
Why this level: It answers yes on all five rubric questions: SSH is exposed on WAN on six-figure numbers of devices, three CVEs are in KEV with confirmed attacks, MikroTik is a home-lab router staple, owning the gateway means owning the LAN, and no credentials are needed. It is also an unauthenticated takeover under active exploitation, which triggers the act-tonight override.
Sources
- MikroTik advisory: September 2026 vulnerability (fixed 7.24.2 / 7.23.4 / 6.49.21)
- CERT Polska: CVE details and affected version ranges
- CERT Polska: actively exploited, IoCs (user -2, 'ops' account, attacker IPs)
- CISA KEV: CVE-2026-86060 and CVE-2026-67277 added 2026-09-10, CVE-2026-67279 added 2026-09-25
- Help Net Security: ~122,500 MikroTik devices with SSH reachable (2026-09-05 scan)
- BleepingComputer: hackers exploit new MikroTik RouterOS flaws
- The Hacker News: how the CVE-2026-67279 + CVE-2026-86060 chain works
How severity is decided. Source file: incidents/2026-09-03-mikrotik-routeros-mikrotrick-ssh.md.