Attackers Hijack MikroTik Routers Through RouterOS Flaws

Attackers are exploiting MikroTik RouterOS flaws to take full control of internet-exposed routers through SSH without authentication.
Attackers are actively exploiting vulnerabilities in MikroTik RouterOS to take full control of vulnerable routers whose SSH services are accessible from the internet.
The warning comes from CERT Polska, which said it has confirmed real-world attacks using a combination of two RouterOS vulnerabilities. The attack chain, which CERT Polska calls “MikroTrick,” can allow attackers to gain full administrative control without valid authentication.
The attacks have been observed since at least September 2, according to CERT Polska. The organization said the vulnerabilities affect several RouterOS components, while MikroTik has already released security updates addressing the issues.
The most serious part of the attack involves two vulnerabilities affecting RouterOS’s SSH functionality.
One of them, CVE-2026-67276, is an SSH authentication bypass with a CVSS score of 9.2. CERT Polska found that RouterOS did not properly verify the complete RSA public key used during authentication. Under certain conditions, an attacker could use a crafted key to access an account without possessing its corresponding private key.
The second, CVE-2026-86060, is also rated 9.2. It involves improper handling of specially crafted usernames during SSH authentication and can allow an attacker to escalate privileges to full administrative access.
When the vulnerabilities are combined, an attacker can take complete control of an internet-accessible RouterOS device without authenticating normally.
CERT Polska has confirmed that this combination is being used in attacks against publicly reachable SSH services. CERT Polska said the attacks it observed left several indicators behind.
One involves failed SSH login attempts associated with a user identified as “-2”, followed by the creation of another account through an SSH session. Another warning sign is the presence of a highly privileged account named “ops.”
The successful attacks analyzed by CERT Polska, including the creation of the “ops” account, originated from the IP address 82.192.72.4 and have been observed since at least September 2. Another address, 103.102.31.18, was seen attempting to exploit the vulnerability chain.
CERT Polska also warns that the absence of these indicators does not necessarily mean a device is clean.
MikroTik released fixed RouterOS versions on September 3, before CERT Polska publicly detailed the vulnerabilities.
The affected releases include RouterOS 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. CERT Polska says these updates prevent the observed attack chain.
MikroTik has also added a “Flagged” mechanism that checks for certain signs of unauthorized changes when RouterOS starts. A compromised device can be marked as “Flagged” and generate a critical log entry.
However, neither MikroTik nor CERT Polska considers the absence of the Flagged status proof that a router has not been compromised. The mechanism only detects selected traces of unauthorized activity.
CERT Polska recommends updating RouterOS immediately and then checking the device for unfamiliar users, scripts, scheduler tasks, proxy settings and tunnels.
If the update cannot be installed immediately, administrators should disable exposed services or restrict access to trusted management networks. CERT specifically recommends paying attention to SSH, WWW/WWW-SSL and the bandwidth-test service.
If there are signs that a router has already been compromised, CERT Polska recommends isolating the device and preserving its logs and configuration before resetting it. The router should then be restored using a trusted configuration, while passwords, keys and other secrets used on the device should be changed.
MikroTik likewise recommends inspecting the configuration for unknown users, scripts or other changes even after installing the security update.
What makes the incident particularly concerning is that this is not simply a newly disclosed vulnerability waiting for attackers to investigate.
CERT Polska has confirmed that the vulnerability combination is already being used against RouterOS devices exposed to the internet, with successful attacks dating back to at least September 2.
At the same time, the available information does not establish who is behind the attacks or how many routers have been compromised. The Hacker News also noted that the evidence does not currently prove that the vulnerabilities were exploited as a zero-day before the patches became available.
For MikroTik administrators, the practical takeaway is fairly simple: update RouterOS, check the logs and configuration, and do not assume that an apparently normal router is clean simply because it has not displayed a warning.
Source: The Hacker News
References in this story
- MikroTik mikrotik.com MikroTik makes networking hardware and software, which is used in nearly all countries of the world. Our mission is to make existing Internet technologies faster, more powerful and affordable to wider range of users.
- MikroTik mikrotik.com MikroTik makes networking hardware and software, which is used in nearly all countries of the world. Our mission is to make existing Internet technologies faster, more powerful and affordable to wider range of users.
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication thehackernews.com Attackers gain full administrative control of MikroTik routers through internet-exposed SSH without authentication, CERT Polska says.



