MikroTrick (CVE-2026-86060, CVSS 9.8): Passwordless Takeover of 122,500 MikroTik Routers — Patch Before Attackers Find Yours
- Three critical CVEs (CVE-2026-67276, CVE-2026-67279, CVE-2026-86060) in MikroTik RouterOS are chained into a single passwordless takeover exploit called “MikroTrick.”
- Active exploitation began September 2, 2026 — one day before patches were released — and continues today against ~122,500 internet-exposed devices.
- A forged RSA key bypasses SSH authentication; a specially crafted username then escalates to full RouterOS administrative access — no password, no SSH key required.
- CISA added CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, 2026.
- Patches are available now: RouterOS 6.49.21, 7.23.4, 7.24.2. If you see a login entry for user “-2” in your SSH logs, your router is already compromised.
Imagine waking up to find your core network routers — devices trusted to ferry every byte across your enterprise — quietly handing administrative control to a stranger sitting thousands of kilometres away. No password. No SSH key. Not even a completed authentication handshake. That is exactly what the “MikroTrick” exploit chain does to unpatched MikroTik RouterOS devices, and as of today, approximately 122,500 internet-exposed MikroTik routers remain vulnerable. If your organisation runs MikroTik gear — and millions of Indian enterprises, ISPs, and branch offices do — this is the most urgent patch you will apply this quarter.
What Is the MikroTrick Exploit Chain?
Poland’s CERT (Cert Polska) issued an emergency advisory in early September 2026 after observing active attacks against RouterOS devices with SSH exposed to the public internet. The agency labelled the three-vulnerability attack sequence “MikroTrick” because of the almost theatrical simplicity with which it breaks open one of the world’s most widely deployed router platforms.
The chain links three distinct flaws:
| CVE | Type | CVSS | Impact |
|---|---|---|---|
| CVE-2026-67276 | SSH RSA key bypass | 9.2 Critical | Authenticate as any known user without private key |
| CVE-2026-67279 | SSH state-machine flaw | Critical | Skip authentication verification during key re-negotiation |
| CVE-2026-86060 | SSH argument injection | 9.8 Critical (CVSS 3.1) | Escalate to full RouterOS administrative privileges |
A fourth vulnerability, CVE-2026-67277 (CVSS 8.8), independently affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or crash and restart the router remotely — even without chaining it to the SSH flaws.
Technical Breakdown: How the Attack Works Step by Step
The elegance — and danger — of MikroTrick lies in how each flaw amplifies the next.
Stage 1 — Forging the Key (CVE-2026-67276 / CVE-2026-67279): RouterOS’s SSH daemon performs incomplete validation of RSA public keys. An attacker who knows a valid username and that user’s RSA public modulus (readable from exported SSH keys or brute-forced) can craft a mathematically different key pair that the server accepts as legitimate. Combined with the SSH state-machine flaw in CVE-2026-67279, an attacker can cause the router to skip the final authentication verification step during key re-negotiation entirely. The result: an unauthenticated SSH session that passes the server’s authentication gate without ever possessing the real private key.
Stage 2 — Privilege Escalation to Admin (CVE-2026-86060): Once inside the partial SSH session, the attacker supplies “-2” as the username parameter. RouterOS’s login handler suffers from improper neutralisation of argument delimiters (CWE-88): it accepts this crafted value and reads the process’s identity and privilege level from file descriptor 2 instead of the credential store, granting full administrative console access. The attacker can now modify users, inject SSH keys, alter firewall rules, plant scripts, configure proxies, or establish covert tunnels — all the capabilities of a legitimate RouterOS super-admin.
Forensic Indicators: Defenders can hunt for compromise using log entries such as login failure for user -2 from <ip> via ssh and user added by ssh:-2@<ip>. A highly privileged account named “ops” appearing without administrator action is another strong indicator. Known attacker IPs observed in the wild include 82.192.72.4 (active since at least September 2) and 103.102.31.18.
Scale and Context: Why MikroTik Matters Particularly in India
MikroTik is not a niche vendor. Its RouterOS platform powers ISP edge routers, enterprise branch offices, hotel networks, retail chains, and campus infrastructure across South Asia. The RouterBOARD product line became a de-facto standard for India’s growing tier-2 and tier-3 ISP market precisely because of its low cost and powerful feature set.
As of early September 2026, Shodan and similar internet-scanning services show roughly 122,500 MikroTik devices with SSH directly exposed to the public internet. The actual number of vulnerable devices is significantly higher once private-network deployments are counted. Attackers who gain administrative access to an ISP’s core RouterOS router can intercept, redirect, or manipulate traffic for thousands of downstream subscribers — a man-in-the-middle attack at national scale.
This threat has direct relevance for Indian organisations. The Computer Emergency Response Team of India (CERT-In) mandates a 6-hour reporting window for significant incidents. A router-level compromise that redirects traffic or exfiltrates data is precisely the class of incident that triggers that obligation. Organisations that delay patching are not only increasing their breach risk — they may be compounding their regulatory exposure. (See also our earlier coverage of similar SD-WAN infrastructure attacks on Arista VeloCloud and the Cisco ISE authentication bypass that threatened zero-trust architectures.)
What You Should Do Right Now — Sanjay Seth’s Defence Playbook
As a practitioner who has hardened networks from Noida to Bengaluru, I have seen organisations treat router patching as a “next quarter” item. MikroTrick removes that option. Here is a prioritised action plan:
- Patch immediately. Upgrade to RouterOS 6.49.21 (for legacy 6.x branches), 7.23.4 (7.x LTS), or 7.24.2 (7.x stable). Check Winbox > System > Packages or run
/system package update check-for-updates. The patches have been available since September 3, 2026 — there is no acceptable reason to remain unpatched. - Hunt for compromise first. Before patching a device, check for indicators:
- Run
/system/device-mode/printand look for a Flagged marker. - Search SSH logs for entries containing
"-2"as a username. - Audit
/ip/userfor unrecognised accounts — especially any named “ops.” - Check
/system/scheduler,/ip/socks,/ip/proxy, and/interface/6to4for unexpected entries.
- Run
- If compromise is confirmed, isolate before you patch. Do not restore from a backup taken after September 2, 2026 — it may contain attacker-planted persistence. Factory-reset the device, apply the patch on clean hardware, then rebuild configuration from a known-good baseline.
- Harden SSH exposure immediately (interim). If you cannot patch right now, disable SSH (
/ip/service disable ssh), restrict the bandwidth-test service, and block WWW/WWW-SSL from public access using a firewall rule. This is a stopgap — not a substitute for patching. - Rotate all credentials and SSH keys. Any SSH key that was ever authorised on a MikroTik device should be considered potentially exposed, as attackers who gained access could have exported them.
- Network segmentation as a failsafe. A zero-trust segmentation model limits the blast radius even when a perimeter device is compromised. If your routers can reach every internal VLAN unrestricted, a compromised router is a compromised network. Segment. Now.
CISA’s Known Exploited Vulnerabilities Listing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities (KEV) catalog on September 10, 2026. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies in the United States were required to remediate these flaws promptly. While BOD 22-01 does not technically bind Indian private-sector organisations, the KEV catalog serves as an authoritative, real-world-exploitation-confirmed list that Indian CISOs and NOC/SOC teams should treat as a mandatory patch priority.
Frequently Asked Questions
My MikroTik device is not directly on the internet. Am I safe?
Not necessarily. If your MikroTik router’s SSH port is reachable from a DMZ, a co-location facility, or a partner network — even without a direct public IP — you remain at risk. Attackers frequently pivot from compromised cloud hosts or ISP segments. The “MikroTrick” chain requires only TCP connectivity to SSH (port 22) on the target device. Verify your firewall rules carefully.
Can I detect if my router was compromised before I patch it?
Yes. The most reliable indicator is a log entry containing user “-2” in an SSH session context. Additionally, inspect /ip/user for unexpected accounts — particularly one named “ops” — and audit scheduled tasks and proxy configurations for anything unfamiliar. Poland’s CERT Polska advisory contains a complete IoC checklist.
We use MikroTik in our branch offices but manage them centrally via The Dude or Winbox. Does that change the risk?
Your management plane may actually increase risk if Winbox or The Dude management traffic traverses the same network segment as internet-facing SSH. An attacker who compromises one branch router can potentially intercept management traffic to pivot to other devices. Segment your management network, use a dedicated out-of-band channel, and patch all devices — not just the internet-facing ones.
Is there a PoC exploit publicly available?
Yes. A proof-of-concept demonstrating the MikroTrick chain is publicly available and has been validated by independent security researchers. MikroTik shipped patches the day after exploitation was first observed in the wild, confirming that active exploitation preceded public disclosure. This is a weaponised vulnerability, not a theoretical one.
The Bottom Line
MikroTrick is a reminder that network infrastructure is attack surface. Routers are not passive conduits — they are privileged nodes that see, route, and can manipulate every packet in your environment. A compromised router is as serious as a compromised domain controller; arguably more so, because it is often trusted by every host on the network without question.
India’s expanding digital infrastructure — from BSNL fibre rollouts to enterprise SD-WAN deployments — increasingly depends on the routers that MikroTick exploits are targeting. The patch has existed since September 3. Every day an organisation waits is a day adversaries are actively looking for that SSH port.
If you are unsure whether your MikroTik estate is fully patched, whether your management network is properly segmented, or whether your NOC has the monitoring coverage to catch the indicators of compromise listed above, reach out to Sanjay Seth for a network security assessment. A one-hour conversation can determine whether your infrastructure is hardened — or whether the “-2” user is already waiting in your logs.
Sources: CERT Polska MikroTik Advisory · BleepingComputer · The Hacker News · SecurityWeek · CISA KEV Catalog · Rescana KEV Analysis