Nora
Blake

MikroTrick RouterOS Exploit Chain Enables Passwordless MikroTik Takeover

Nora Blake

Sep 24, 2026

8 min read

MikroTrick RouterOS Exploit Chain Enables Passwordless MikroTik Takeover

TL;DR

MikroTrick chains two RouterOS SSH vulnerabilities to gain full administrative access without completing authentication.

  • CERT Polska confirmed exploitation against RouterOS devices with SSH exposed to public networks.
  • Update to a fixed RouterOS release, restrict management access, and investigate documented compromise indicators.
  • Hexnode XDR and UEM can support downstream endpoint investigation and compliance visibility, but do not replace RouterOS remediation.

MikroTrick is a two-vulnerability exploit chain that can give attackers full administrative access to vulnerable MikroTik RouterOS devices without a password or SSH key.

CERT Polska found that CVE-2026-67279 can move an unauthenticated SSH connection into channel handling after a client-triggered rekey. CVE-2026-86060 then lets an attacker manipulate the policy mask passed to the RouterOS login process. Combined, the flaws open a fully privileged administrative console without completing user authentication.

MikroTik released fixes on September 3, 2026, in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). The fix was also included in 7.25beta3. MikroTik advised administrators not to expose SSH or other management services to untrusted networks.

MikroTrick at a Glance

Detail  Information 
Product  MikroTik RouterOS 
Exploit chain  CVE-2026-67279 + CVE-2026-86060 
CVE-2026-67279  Improper enforcement of behavioral workflow (CWE-841) affecting the SSH authentication state machine 
CVE-2026-86060  Argument injection (CWE-88) in the RouterOS SSH login path 
Prerequisite  Attacker can reach the RouterOS SSH service; confirmed in-the-wild attacks targeted devices with SSH accessible from public networks. 
Potential impact  Full unauthenticated administrative console access 
Fixed releases  6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable); fix also included in 7.25beta3 
Exploitation evidence  Public attack logs date to September 2, 2026 
CISA KEV  CVE-2026-86060 added September 10, 2026 

CERT Polska’s technical analysis identifies CVE-2026-67279 and CVE-2026-86060 as the two vulnerabilities that form the MikroTrick exploit chain.

CVE-2026-86060 carries a CVSS v4.0 score of 9.2. CERT Polska classifies CVE-2026-67279 as an improper enforcement of behavioral workflow vulnerability (CWE-841).

How an SSH Rekey Lets MikroTrick Skip Authentication

The first part of MikroTrick breaks the expected order of SSH operations.

SSH first establishes the protected transport and then authenticates the user. After successful authentication, the SSH connection protocol can open channels for functions such as shells and command execution.

RouterOS versions affected by CVE-2026-67279 mishandled a client-initiated SSH rekey during user authentication. When that rekey finished, the SSH server moved into channel handling instead of returning to the interrupted authentication stage.

Consequently, RouterOS could accept a session channel even though it had never sent the normal SSH_MSG_USERAUTH_SUCCESS message.

However, this flaw alone does not create an authenticated identity or assign administrative privileges. Instead, it provides the unauthenticated session channel required for the second vulnerability.

How the -2 Username Turns the Bypass Into Full Admin Access

CVE-2026-86060 provides the second stage of MikroTrick. It allows an attacker who reaches the RouterOS login helper to supply an attacker-controlled policy mask.

RouterOS uses /nova/bin/login to create the console. The SSH daemon passes the username and effective policy mask to this program as command-line arguments.

Before the patch, RouterOS did not adequately validate the username before passing it to login. Therefore, a username beginning with a hyphen could be interpreted as an option rather than an ordinary username.

The attacker uses -2 as the username.

The login program interprets -2 as an instruction to read identity and policy information from file descriptor 2. That descriptor points to the pseudoterminal established for the SSH session.

File descriptors 0, 1, and 2 used by the login process share the pseudoterminal’s input queue. Therefore, an attacker can send data through the SSH channel that login then uses as the effective policy mask.

Combined with CVE-2026-67279, this produces full unauthenticated access to the RouterOS administrative console.

The two-stage dependency is what makes the attack distinctive:

SSH rekey state error → unauthenticated session channel → -2 argument injection → attacker-controlled policy mask → administrative console

What the Pre-Patch MikroTrick Activity Revealed

CERT Polska found the earliest publicly available attack logs dated September 2, 2026. This was one day before MikroTik published the patched RouterOS releases.

Public reports repeatedly contained three indicators: connections from 82.192.72.4, an authentication attempt using -2, and creation of an ops account with full privileges.

One published diagnostic report showed rejected authentication, rekeying, channel creation, and command delivery. On that particular router, however, the SSH process crashed before the attack completed.

Other reports documented successful creation of the privileged account. CERT Polska also identified cases where a RIF diagnostic file was created and data was then transferred to 82.192.72.4 using RouterOS fetch.

The researchers described the sequence as strongly suggesting diagnostic-file exfiltration.

CERT Polska subsequently confirmed that attackers were exploiting MikroTrick in the wild to take full control of RouterOS devices with SSH accessible from public networks.

CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10.

How Enterprises Should Check MikroTik Routers for MikroTrick

Updating RouterOS to a release containing the MikroTrick fixes prevents the observed attacks, but administrators should still inspect the device for unauthorized configuration changes and other signs of prior compromise.

After updating, administrators should check the RouterOS logs for a critical entry showing that RouterOS marked the device as Flagged. They should also review the configuration for unknown users, scripts, or other unrecognized changes. The Flagged mechanism detects only selected compromise artifacts, so a router without a Flagged state may still be compromised.

Look specifically for:

  • SSH login attempts involving user -2
  • An unexpected ops account with full privileges
  • Unknown users, scripts, or scheduler entries
  • Unrecognized tunnels or proxy configurations
  • Unexpected RIF diagnostic files
  • Unexplained fetch activity
  • SSH attack activity originating from 82.192.72.4, which CERT Polska associated with successful observed attacks
  • Exploitation attempts involving 103.102.31.18, which CERT Polska associated with attempted exploitation rather than the successful attacks documented from 82.192.72.4

These artifacts should be treated as indicators requiring investigation. Their absence does not establish that a device was not compromised.

If the Flagged marker, logs, configuration, or other evidence indicates possible compromise, isolate the router and preserve its logs and configuration before resetting it. Report information about the observed attack to the appropriate CSIRT according to its instructions. Do not clear the Flagged marker until the analysis is complete and evidence has been secured. Then restore the device to factory settings and reconfigure it from trusted, verified configuration data.

Administrators should also change passwords, keys, and other secrets in use. They should not blindly restore a full configuration backup from a potentially compromised router.

Organizations should upgrade to a fixed RouterOS release and prevent SSH access from untrusted networks. Management access should be limited to trusted IP addresses or a protected management path such as a VPN.

MikroTik specifically recommends using a strong VPN such as WireGuard for remote management instead of exposing management ports directly to the internet.

Router remediation addresses the compromised infrastructure. Security teams may also need to investigate managed endpoints behind the affected network for suspicious activity.

Investigate Downstream Endpoint Activity with Hexnode

A successful MikroTrick attack can give an attacker full control of the affected RouterOS device at the network edge. Organizations may then broaden their investigation to systems behind the router. However, CERT Polska has not reported downstream endpoint compromise in the observed MikroTrick activity.

Network administrators should handle the RouterOS response separately by applying the available fixes and restricting management access. If they find signs of compromise, they should isolate the router, preserve relevant evidence, and then reset and reconfigure it using trusted configuration data. Endpoint security teams can then examine managed endpoints for signs of related malicious activity.

Hexnode XDR supports this endpoint side of the investigation. It supports endpoint investigation and threat hunting through a query engine that administrators can use to examine actionable endpoint data.

If malicious endpoint activity is identified, Hexnode XDR provides response actions such as Isolate Device, Kill Process, and Quarantine File. These controls can help contain activity on affected endpoints while network administrators remediate the compromised router.

Hexnode UEM can complement this investigation by providing visibility into managed-device compliance. Administrators can identify endpoints that no longer meet configured compliance requirements and review their compliance status.

The responsibilities remain distinct: RouterOS updates prevent the observed MikroTrick attacks, while investigation and recovery steps address possible prior router compromise; endpoint security controls operate separately on supported endpoints in the environment.

Why-XDR-IS-stronger-thumbnail

Why XDR Is Stronger With UEM

See how Hexnode UEM and XDR combine endpoint context, security visibility, and response workflows to support faster threat investigation and containment.

Download the whitepaper

MikroTrick Makes Router Inspection as Important as Patching

MikroTrick demonstrates why patching an exposed network appliance is only one part of incident response.

The chain first breaks RouterOS’s SSH authentication state machine. It then uses attacker-controlled input to influence the policy mask passed to the login process.

CERT Polska confirmed that MikroTrick was exploited in the wild to take full control of RouterOS devices with SSH accessible from public networks. The earliest publicly available attack logs date to September 2, 2026, before MikroTik released the fixes.

Therefore, enterprises running affected MikroTik RouterOS versions should update to a fixed release and restrict management interfaces from untrusted networks.

Teams should also inspect routers for the documented indicators. If they suspect compromise, they should preserve evidence, rebuild the affected router from trusted configuration data, rotate relevant secrets, and assess systems behind the router for related suspicious activity.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.