MikroTrick: Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password
CERT Polska disclosed six MikroTik RouterOS vulnerabilities, with two critical ones chained as MikroTrick (CVE-2026-67276 and CVE-2026-86060). The attack needs no password or key: an SSH public-key verification bypass plus argument injection grants administrator access. CISA added both CVEs to its Known Exploited Vulnerabilities catalog, with over 122,000 devices affected.
- CVE-2026-67276: RSA key exponent is not checked during SSH authentication
- CVE-2026-86060: username argument injection escalates to administrator privileges
- MikroTik shipped patches 6.49.21, 7.23.4, 7.24.2 and 7.23.5
- CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 10
Read next
Security