The critical MikroTrick exploit chain bypasses MikroTik RouterOS SSH auth to grant root access. Learn the threat mechanics, IoCs, and remediation protocols.
A critical remote, pre-authentication takeover chain tracked as "MikroTrick" is actively compromising internet-facing MikroTik RouterOS edge devices. Disclosed by CERT Polska, which named the chain after combining two of six RouterOS flaws, the attack pairs an SSH authentication flaw with command-line argument injection in the SSH login helper (CVE-2026-86060). CERT Polska's advisory describes the RSA validation bypass CVE-2026-67276 and CVE-2026-86060 as separate flaws and does not name which two form the chain; CISA says CVE-2026-67279 can be chained with CVE-2026-86060 (see the update below). Remote unauthenticated adversaries can bypass administrative credentials entirely to spawn an interactive, fully privileged root session. Network appliances keep drawing this exact attack pattern, including Cisco ISE's zero-day granting unauthenticated remote admin access. Internet-wide scanning telemetry from the Shadowserver Foundation identified over 122,500 exposed MikroTik SSH interfaces reachable on port 22 during active exploitation.
Updated RouterOS releases—specifically 7.25beta3, 7.24.2, 7.23.4, and 6.49.21—patch both entry flaws. However, firmware updates alone do not disinfect previously compromised units, leaving behind backdoors such as rogue user accounts, scheduled reverse shells, and covert SOCKS proxies. Magento operators learned the same lesson with CosmicSting backdoors and StyleSmuggler skimmers. Furthermore, MikroTik's automated boot-time integrity check cannot guarantee that an unflagged system is clean. Reclaiming affected infrastructure requires volatile evidence preservation, full flash re-imaging via Netinstall, and network isolation of the perimeter management plane.
Update, 3 October 2026: CISA added CVE-2026-67279, a MikroTik RouterOS "Improper Enforcement of Behavioral Workflow" flaw (CWE-841) in the SSH server's rekey handling, to its Known Exploited Vulnerabilities catalog on 25 September 2026, with a federal due date of 28 September. CISA's entry says it can be chained to achieve unauthenticated exploitation of CVE-2026-86060, which CISA had already added to KEV on 10 September. NVD scores CVE-2026-67279 at CVSS 3.1 6.5 (Medium) and CERT Polska at CVSS 4.0 6.9. It is fixed in 6.49.21, 7.23.4 and 7.24.2. CVE-2026-67276, the RSA exponent flaw, is a separate entry in the same advisory and is not listed in KEV. This update also corrects the patched-version and score details for the CVEs below.
Anatomy of the MikroTrick Chain: Cryptographic Bypass to Root Access
MikroTrick transitions an unauthenticated TCP connection on port 22 directly into a root-equivalent administrative session by exploiting two sequential flaws in the RouterOS SSH daemon. CI/CD infrastructure has faced comparably blunt auth bypasses too, as our coverage of a critical Jenkins CLI flaw weaponized for ransomware shows.
Note (3 October 2026): The diagram shows the RSA bypass as the first stage. CERT Polska's advisory does not say which two of the six flaws make up MikroTrick, and CISA's KEV entry links CVE-2026-67279, not CVE-2026-67276, to CVE-2026-86060. Treat Stage 1 as one illustrative authentication-bypass path.
CVE-2026-67276: Cryptographic RSA Modulus Validation Bypass
- CVSS Score & Severity: CVSS 4.0 9.2 (Critical, CERT Polska); CVSS 3.1 8.1 (High, NVD) | CWE: CWE-347 | Affects: RouterOS 7.x only; fixed in 7.23.4 and 7.24.2
When an inbound SSH client requests public-key authentication (publickey), the RouterOS SSH daemon compares the user's stored public key against the key sent in the handshake. However, the verification routine evaluates only the key algorithm identifier and the public modulus ($N$), omitting validation of the public exponent ($e$).
Under standard RSA mathematics, verification evaluates:
$$S^e \equiv M \pmod N$$
By supplying an authorized system modulus $N$ alongside a rogue public exponent of $e = 1$, the equation simplifies to:
$$S^1 \equiv M \pmod N \implies S = M$$
The attacker signs the payload using their own parameters with $e = 1$. Because RouterOS validates the signature against client-supplied parameters rather than the key stored on disk, the signature validates without the attacker possessing the private key ($d$).
CVE-2026-86060: SSH Login Argument Injection
- CVSS Score & Severity: CVSS 4.0 9.2 (Critical, CERT Polska); CVSS 3.1 9.8 (Critical, NVD) | CWE: CWE-88
After cryptographic verification succeeds, the SSH service dispatches the username to an internal authentication and policy helper. RouterOS fails to enforce character allowlists or argument delimiters on username strings. When an adversary supplies a username starting with a hyphen—specifically -2—the login helper interprets the string as a command-line flag rather than an identity. This argument injection overwrites the session security policy bitmask to 0xFFFFFFFF, granting full administrative rights across all subsystems (write, policy, test, password, sniff, sensitive).
Vulnerability Disambiguation: CVE-2026-67277 Initial reporting frequently conflated MikroTrick with CVE-2026-67277 (CVSS 8.8, CWE-306). That vulnerability resides in the RouterOS bandwidth-test daemon (
btest), where unauthenticated clients trigger uninitialized kernel packet buffer leaks and integer-underflow crashes. It does not provide the interactive SSH administrative access seen in MikroTrick.
Threat Telemetry and In-the-Wild Indicators
Threat intelligence from CERT Polska confirmed weaponization in early September 2026, observing attackers hijacking edge gateways to build bulletproof proxies, anonymization hops, and network pivots. SSH-adjacent trust failures have hit other infrastructure too, such as HashiCorp Vault's root host takeover via blank SSH certificates.
| Indicator / Artifact | Type | Context & Detection Value |
|---|---|---|
82.192.72.4 | IPv4 Address | Primary attacking source executing takeovers and creating backdoor accounts. |
103.102.31.18 | IPv4 Address | Secondary infrastructure conducting mass SSH scans and exploit attempts. |
ops | Local Username | High-privilege backdoor account injected into the full user group. |
login failure for user -2 from <IP> via ssh | Syslog Signature | Generated when the login helper processes the argument-injected username. |
user <name> added by ssh:-2@<IP> | Syslog Signature | Confirms privilege escalation and administrative user creation. |
Correlated edge device logs capture the exact sequence of unauthorized elevation:
2026-09-02 03:14:11 system,error,critical login failure for user -2 from 82.192.72.4 via ssh
2026-09-02 03:14:12 system,info,account user ops added by ssh:-2@82.192.72.4
2026-09-02 03:14:13 system,info,account user ops group set to full by ssh:-2@82.192.72.4
Auditing the Edge: Detection Limits of the "Flagged" Status
Patched RouterOS releases incorporate a boot-time integrity assessment readable via the command line:
[admin@Edge-Router] > /system/device-mode/print
mode: enterprise
flagged: yes
At boot, RouterOS scans configuration files and system memory for known exploit signatures. If recognized markers are found, it disables the malicious artifacts, logs a critical alert, and marks the device as flagged: yes.
Detection Limits: The automated scanner relies strictly on static heuristics matching known initial attack scripts. Threat actors modifying payload filenames, altering firewall rules, or deploying memory-resident scripts will evade detection. CERT Polska explicitly warned that the absence of the marker does not prove a device is uncompromised. A flagged: no response still warrants a comprehensive configuration audit.
Engineers must manually audit configuration surfaces across six persistent subsystems:
# Inspect administrative users, automation scripts, and recurring schedulers
/user print detail where group="full"
/system script print detail
/system scheduler print detail
# Detect unauthorized SOCKS proxies, NAT pivots, packet sniffers, and DNS resolvers
/ip socks print
/ip firewall nat print detail where action="dst-nat" or action="redirect"
/tool sniffer print
/ip dns print
Edge Remediation and Recovery Protocol
Firmware upgrades close the initial attack vector but cannot remove established persistence. Other edge vendors have learned that the hard way too, as Akira ransomware exploiting a critical SonicWall flaw despite firmware updates showed. Soft resets (/system reset-configuration) fail to purge malicious modifications written to internal flash. Complete recovery requires a structured four-stage process:
- Forensic Evidence Collection: Prior to taking the device offline, export the running configuration and system logs to a secure workstation:
/export verbose hide-sensitive=no file=forensic_config
/log print detail file=forensic_logs
- Netinstall Flash Re-image: Disconnect all WAN and LAN cables. Connect
Ether1directly to an isolated administration machine. Boot into Netinstall mode by holding the hardware reset button during power-on. Flash an official.npkimage (v7.24.2Stable orv7.23.4Long-Term) withkeep-old-configuration=noto format flash memory and reinstall the kernel. - Pristine Configuration Reconstruction: Never restore binary
.backupfiles from a compromised router. Re-apply configurations exclusively using audited, plain-text.rscimport scripts, and rotate all local passwords, BGP/OSPF secrets, IPsec pre-shared keys, and WireGuard credentials. - Management Plane Hardening: Restrict management interfaces to private networks and drop WAN access:
/ip service set ssh port=2222 address=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
/ip service disable telnet,ftp,www,api,api-ssl
/ip firewall filter add chain=input action=drop in-interface-list=WAN comment="Block WAN management"
CISA KEV Update: CVE-2026-67279 Joins the Catalog
On 25 September 2026, CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities (KEV) catalog, with a federal remediation due date of 28 September 2026. It is the second MikroTik SSH flaw tied to this campaign to enter KEV: CVE-2026-86060 (and the btest flaw CVE-2026-67277) were added on 10 September 2026.
NVD describes CVE-2026-67279 (CWE-841) as a protocol state error: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted. An unauthenticated client can then open a session channel and send an exec request, which affected builds dispatch. CISA's KEV entry states the flaw "can be chained to achieve unauthenticated exploitation of CVE-2026-86060", which gives attackers a second route to the argument-injection stage alongside the RSA bypass described above.
NVD scores it CVSS 3.1 6.5 (Medium); CERT Polska scores it CVSS 4.0 6.9. Read alone, that score understates the risk, because the chained exploitation is what landed it in KEV. Affected builds are 6.x before 6.49.21, 7.x before 7.23.4, and 7.24.x before 7.24.2. The fix ships in 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable), the same releases that patch CVE-2026-86060. CVE-2026-67276 affects only the 7.x branch and is fixed in 7.23.4 and 7.24.2.
CVE-2026-67279 entered CISA KEV 15 days after CVE-2026-86060; both are fixed in RouterOS 6.49.21, 7.23.4 and 7.24.2.
Summary of September 2026 RouterOS Security Disclosures
The September 2026 security release addresses several vulnerabilities across the operating system:
| CVE ID | Subsystem | CVSS & Severity | Core Vulnerability Mechanism | Patched In |
|---|---|---|---|---|
| CVE-2026-67276 | SSH Server | 9.2 (Critical, CVSS 4.0) | Omits RSA exponent $e$ validation; verifies forged signatures using $e=1$. | 7.24.2, 7.23.4 (7.x only) |
| CVE-2026-86060 | SSH Auth Helper | 9.2 (Critical, CVSS 4.0) | Unsanitized username (-2) injected as execution flag, elevating policy bitmask. | 7.25beta3, 7.24.2, 7.23.4, 6.49.21 |
| CVE-2026-67277 | Bandwidth-Test | 8.8 (High) | Pre-auth state transition leaks packet buffers and causes integer-underflow DoS. | 7.25beta3, 7.24.2, 7.23.4, 6.49.21 |
The update bundle also resolves three secondary flaws: CVE-2026-67279 (CVSS 3.1 6.5 from NVD, now in CISA KEV), an SSH rekey flaw that lets an unauthenticated client run exec requests and create or overwrite files; CVE-2026-67281 (CVSS 3.1 7.5 from NVD), a stale pointer dereference in the WebFig proxy (/jsproxy) allowing credential file disclosure; and CVE-2026-67278 (CVSS 4.0 6.3 from CERT Polska, CVSS 3.1 9.1 from NVD), which improperly validates PKCS#1 v1.5 signatures against $e=3$ root certificates. Per its CVE record, releases 7.23.4 and 7.24.2 carried an incomplete fix for CVE-2026-67278; it is fully fixed in 7.23.6 and 7.24.3.
Network defenders must treat internet-facing RouterOS devices as critical trust boundaries. The same isolation logic applies to SD-WAN control planes, per our coverage of Arista VeloCloud Orchestrator's zero-day demanding management-plane isolation. Mitigating MikroTrick requires immediate firmware updates, rigorous verification of device integrity beyond the automated "Flagged" check, and absolute containment of administrative interfaces behind private, out-of-band management networks.
Sources
- CERT Polska: Critical vulnerabilities in MikroTik RouterOS are being actively exploited
- CERT Polska: MikroTik RouterOS CVE advisory
- NVD: CVE-2026-67279
- NVD: CVE-2026-86060
- NVD: CVE-2026-67276
- NVD: CVE-2026-67278
- CISA Known Exploited Vulnerabilities catalog: CVE-2026-67279
- CISA KEV catalog JSON feed
- MikroTik: September 2026 vulnerability advisory