MikroTrick: log indicators and forensic checks for the RouterOS chain
CERT Polska detailed the MikroTrick chain of two RouterOS flaws (CVE-2026-67279 and CVE-2026-86060), fixed in MikroTik's 3 September 2026 releases. Exploitation leaves a telltale log pair: a failed login for user -2 followed by creation of an ops account with full policy.
- Affected branches: RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21
- A successful chain grants full admin console access, VPN keys and routing control
- An ops account with full policy you did not create is a compromise indicator
- ZoomEye found 9,559 RouterOS devices with SSH exposed to the internet
Read next
Security