Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

MikroTik Routers Hijacked Via Exploited Flaws

Published 7 September 2026

Attackers are actively exploiting a chain of vulnerabilities in MikroTik's RouterOS software to gain unauthorized administrative control of devices, particularly those with SSH services exposed to the internet. The exploit, dubbed MikroTrick, allows attackers to hijack devices without authentication by combining at least two critical security flaws. The vulnerabilities were discovered by CERT Polska, Poland's national cybersecurity incident response team. One of the key flaws, identified as CVE202667276, is an SSH authentication bypass. It stems from RouterOS improperly validating RSA public keys, allowing an attacker who knows a username and the public modulus of that user's key to craft a different key and log in without needing the legitimate private key. This is compounded by a privilege escalation vulnerability, CVE202686060, which arises from how RouterOS handles specially crafted usernames, enabling attackers to gain full administrative privileges. A third vulnerability affecting the bandwidthtest service, CVE202667277, can also be exploited to leak kernel memory or crash devices.

0:00 / 0:00