Hackers are chaining CVE-2026-67276 and CVE-2026-86060 in MikroTik RouterOS to bypass SSH authentication and gain full administrative control of internet-exposed routers. Poland’s CERT says the “MikroTrick” exploit chain is actively being used in the wild, while MikroTik has released fixes and added compromise-detection features. #MikroTrick #CVE-2026-67276 #CVE-2026-86060 #MikroTik #RouterOS
Keypoints
- Attackers are chaining two MikroTik RouterOS vulnerabilities to take over exposed SSH services.
- CVE-2026-67276 enables SSH authentication bypass through incomplete RSA public key validation.
- CVE-2026-86060 allows privilege escalation via specially crafted usernames.
- Poland’s CERT calls the exploit chain “MikroTrick” and says it is actively exploited.
- MikroTik has issued fixes and added detection mechanisms, but exposed SSH services remain at risk.