MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
CERT Polska says two MikroTik RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, can be chained to give attackers full administrative control of Internet-exposed routers without a password or completed authentication. Evidence of exploitation appeared before patches were released, with logs showing the suspicious SSH username -2 and post-exploitation activity tied to accounts like ops. #MikroTik #RouterOS #CVE-2026-67279 #CVE-2026-86060 #CERTPolska #CISA

Keypoints

  • Two RouterOS SSH flaws can be chained to gain full admin access.
  • CVE-2026-67279 bypasses normal SSH authentication flow.
  • CVE-2026-86060 enables argument injection in the login process.
  • Attack logs show exploitation attempts using the username -2.
  • Administrators should patch, inspect devices, and rebuild compromised systems.

Read More: https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html