Active exploitation of the MikroTrick vulnerability chain is allowing attackers to take over internet-exposed MikroTik RouterOS devices without credentials. The attack combines an SSH rekeying authentication-state bypass—reported as CVE-2026-67279 (though one advisory lists CVE-2026-67277)—with CVE-2026-86060, in which a crafted username can make the RouterOS login helper accept an attacker-controlled privileged identity. Researchers reproduced full administrative compromise on vulnerable RouterOS 7.x systems, enabling access-control bypass, persistence, and potential lateral movement into connected networks; CISA has added the flaws to its Known Exploited Vulnerabilities catalog.
MikroTik has issued fixes in RouterOS 6.49.21, 7.23.4, 7.24.2, and subsequent applicable releases. Organizations should immediately patch exposed routers, restrict external exposure of Winbox and API services, and audit administrator accounts. They should also investigate devices for attacker-created privileged accounts, scripts, and scheduled tasks, because patching alone will not remove persistence or rotate credentials that may have been exposed during compromise.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CERT Polska published an advisory covering six MikroTik RouterOS vulnerabilities that could be combined into the MikroTrick takeover chain. MikroTik addressed the issues in RouterOS 6.49.21, 7.23.4, 7.24.2, and later applicable releases.
CERT.UG/CC warned that the active MikroTrick campaign could enable unauthenticated device takeover, persistence, and lateral movement from compromised routers. It urged administrators to update RouterOS, restrict untrusted Winbox and API access, and audit administrator accounts.
During authorized testing, Bishop Fox observed internet-facing MikroTik routers with artifacts consistent with the campaign, including privileged accounts, a logrotate script, and a daily-maint scheduler that recreated a full-privilege account. The observed scripts and scheduler objects used a numeric owner value of "0," though the researchers noted this is only a hunting lead.
Bishop Fox reproduced unauthenticated administrative compromise of vulnerable RouterOS 7.x systems using CVE-2026-67279's SSH rekeying authentication-state bypass and CVE-2026-86060's crafted-username flaw. Its detector was validated as vulnerable on RouterOS 6.49.20 and 7.23.3 and fixed on 6.49.21 and 7.23.4.
CISA added the RouterOS vulnerabilities identified as CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities catalog, with a September 13, 2026 remediation deadline for U.S. federal agencies.
Evidence cited by Bishop Fox indicates that attackers exploited vulnerable internet-exposed MikroTik RouterOS devices before the underlying vulnerabilities were publicly disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
bishopfox.com
Open sourcecert.ug
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.