Hackers exploit new MikroTik RouterOS flaws to hijack routers

Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are chaining CVE-2026-67276 and CVE-2026-86060 in MikroTik RouterOS to bypass SSH authentication and gain full administrative control of internet-exposed routers. Poland’s CERT says the “MikroTrick” exploit chain is actively being used in the wild, while MikroTik has released fixes and added compromise-detection features. #MikroTrick #CVE-2026-67276 #CVE-2026-86060 #MikroTik #RouterOS

Keypoints

  • Attackers are chaining two MikroTik RouterOS vulnerabilities to take over exposed SSH services.
  • CVE-2026-67276 enables SSH authentication bypass through incomplete RSA public key validation.
  • CVE-2026-86060 allows privilege escalation via specially crafted usernames.
  • Poland’s CERT calls the exploit chain “MikroTrick” and says it is actively exploited.
  • MikroTik has issued fixes and added detection mechanisms, but exposed SSH services remain at risk.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/