MikroTik patches MikroTrick SSH chain that can seize routers

MikroTik released fixes for six RouterOS flaws after CERT Poland confirmed two chained bugs, called MikroTrick, are being used to bypass SSH and take full control of routers.

MikroTik released patches for six vulnerabilities in its RouterOS software after CERT Poland confirmed two of the flaws are being chained in active attacks to bypass SSH authentication and take control of affected devices.

CERT Poland reported the combined flaws, dubbed MikroTrick, have been used since at least Sept. 2 to create an account named “ops” and to gain full control of routers whose SSH service is reachable from public networks. The agency advised that updating to the latest RouterOS versions prevents these attacks.

The most severe issues include CVE-2026-67276, an SSH authentication bypass with a CVSS score of 9.2; CVE-2026-86060, an SSH session privilege manipulation flaw also scored 9.2; and CVE-2026-67277, a memory disclosure and denial-of-service weakness scored 8.8. The patch release also addresses CVE-2026-67278, which can enable TLS server impersonation; CVE-2026-67279, which allows unauthenticated file tampering including configuration files; and CVE-2026-67281, which permits disclosure of root-owned files and configuration stores.

MikroTik described the update as an important security release and noted most configurations are not at risk. The company recommended blocking SSH access from untrusted sources and checking the device log for a “Flagged” entry as an indicator of compromise. MikroTik listed RouterOS versions 7.25beta3, 7.24.2, 7.23.4 and 6.49.21 as containing the fixes and urged administrators to apply them promptly.

CERT Poland identified two IP addresses as sources of the observed attacks: 82.192.72.4 and 103.102.31.18. The agency said the presence of the “ops” account or those IPs in logs indicates an exploitation attempt and should be investigated, while the absence of those traces does not rule out unauthorized activity.

A Shadowserver Foundation scan on Sept. 5 found more than 120,000 MikroTik devices with SSH reachable from the internet during a 24-hour window, highlighting the number of devices exposed when SSH is left accessible from public networks.

Network administrators are advised to update affected routers to the patched RouterOS versions, limit SSH exposure to trusted networks, and review account lists and logs for signs of the “ops” account or traffic from the identified IP addresses.

Articles by this author