Security researchers have disclosed a powerful exploit chain dubbed MikroTrick that allows attackers to gain full administrative control of internet-facing MikroTik routers without requiring a password, SSH key, or successful user authentication.
The attack combines two critical RouterOS vulnerabilities: CVE-2026-67279, an SSH state-machine flaw, and CVE-2026-86060, an argument-injection vulnerability in the RouterOS login mechanism. According to CERT Polska, evidence suggests the flaws were exploited in the wild as early as September 2, 2026, a day before MikroTik released security updates in RouterOS versions 6.49.21, 7.23.4, and 7.24.2.
Exploitation Confirmed Prior to Public Disclosure
CERT Polska initially warned on September 5 that attackers were actively compromising RouterOS devices exposed to the internet through SSH services. While the original advisory confirmed ongoing attacks and urged immediate patching, it did not disclose the specific vulnerabilities involved or explain how they worked together. The latest research sheds light on the complete attack chain.
Breaking SSH Authentication
Under normal circumstances, SSH follows a strict process: an encrypted connection is established, the user is authenticated, and only then can commands be executed. Successful authentication is confirmed through a message known as SSH_MSG_USERAUTH_SUCCESS.
The first vulnerability, CVE-2026-67279, disrupts this sequence. Researchers found that if an attacker forces an SSH key renegotiation while authentication is still in progress, vulnerable RouterOS systems incorrectly transition to the command-execution stage once renegotiation completes. As a result, an unauthenticated user can access functionality that should only be available after a successful login.
Although this flaw alone does not provide authenticated access or elevated privileges, it allows attackers to bypass a critical security boundary and reach a phase of the SSH protocol that should remain inaccessible.
Turning Access Into Full Administrative Control
The second vulnerability, CVE-2026-86060, enables attackers to transform that unauthorized access into complete system compromise.
RouterOS launches a login component called /nova/bin/login, passing the supplied username and privilege information as command-line parameters. However, the application fails to properly validate usernames before processing them.
Attackers exploit this behavior by submitting "-2" as the username. Because the value begins with a hyphen, the login application interprets it as a command-line option rather than a username. This option instructs the program to retrieve identity and privilege details from file descriptor 2, which corresponds to the active SSH terminal.
By preloading the terminal with a chosen username and administrative privilege values, attackers can trick the login process into granting a fully privileged administrative session, effectively taking complete control of the device.
Signs of Real-World Attacks
Researchers identified a unique indicator associated with the exploit chain: failed SSH login attempts using the username "-2". Reports containing this pattern appeared on MikroTik community forums on September 2, suggesting attackers were exploiting the vulnerabilities before security patches became available.
One incident analyzed by CERT Polska showed a sequence involving:
- A failed authentication attempt for user "-2"
- Forced SSH renegotiation
- Transition into the SSH channel phase without authentication
- An attempt to create a new administrative account named "ops"
Although the SSH process crashed before the command completed in that particular case, other affected devices reportedly had the ops account successfully created with full administrative privileges.
Investigators also observed attackers generating diagnostic files and transferring data to external infrastructure, indicating that sensitive configuration information may have been exfiltrated from compromised routers.
Clarifying Related Vulnerabilities
CERT Polska emphasized that the MikroTrick attack chain only involves CVE-2026-67279 and CVE-2026-86060.
Some reports incorrectly linked CVE-2026-67276 to the chain. Researchers clarified that this is a separate SSH vulnerability that allows forged RSA-key authentication against a specific existing user account when an attacker already knows the username and corresponding public key. Unlike MikroTrick, it does not provide unrestricted administrative access.
Adding further weight to the findings, CISA included CVE-2026-86060 in its Known Exploited Vulnerabilities (KEV) catalog on September 10, confirming active exploitation in the wild.
Exposure Depends on SSH Accessibility
Successful exploitation requires attackers to be able to reach the router's SSH service.
MikroTik noted that SSH is not exposed to the internet in its default home-router configuration. However, organizations and administrators who modified firewall rules or manage devices remotely over SSH from untrusted networks face significantly greater risk.
At present, no official estimate has been released regarding the number of devices compromised through the attack chain.
What Administrators Should Do
Installing security updates prevents future exploitation but does not remove malicious changes already made by attackers.
After applying patches, administrators should review the device's Flagged status:
MikroTik and CERT Polska caution that the Flagged indicator detects only selected signs of compromise, meaning a clean result should not be treated as proof of safety.
Indicators of Compromise
Administrators should investigate for the following artifacts:
- SSH login attempts using the username -2
- An account named ops assigned to the full-privilege group
- Connections involving 82.192.72.4 (observed in successful compromises)
- Connections involving 103.102.31.18 (observed during exploitation attempts)
- Unknown user accounts
- Suspicious scripts or scheduled tasks
- Unauthorized tunnels or proxy configurations
- Unexpected .rif diagnostic files
- Unexplained file retrieval or data-transfer activity
Incident Response Recommendations
If compromise is suspected, CERT Polska recommends:
- Immediately isolating the affected router.
- Preserving logs, forensic evidence, and configuration data.
- Performing a factory reset.
- Rebuilding the system from a trusted configuration source.
- Rotating all passwords, cryptographic keys, and other credentials.
- Avoiding restoration from backups created after compromise.
Researchers noted that AI-assisted tools, including OpenAI's GPT-5 cyber-focused models and locally hosted open-source models, were used to automate portions of protocol analysis and laboratory testing during the investigation. However, all findings were ultimately validated against real RouterOS systems before publication.
The disclosure highlights the growing threat posed by internet-exposed network infrastructure and reinforces the need for timely patching and restricted SSH access on MikroTik deployments.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
