chiprook
← Security
SecurityOctober 8, 2026, 22:00

MikroTrick: Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password

CERT Polska disclosed six MikroTik RouterOS vulnerabilities, with two critical ones chained as MikroTrick (CVE-2026-67276 and CVE-2026-86060). The attack needs no password or key: an SSH public-key verification bypass plus argument injection grants administrator access. CISA added both CVEs to its Known Exploited Vulnerabilities catalog, with over 122,000 devices affected.

MikroTrick: Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password
#MikroTik#RouterOS#CISA
Read next
Security

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Security

MikroTrick: log indicators and forensic checks for the RouterOS chain

Security

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers

Security

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers