#6
The Hacker News
general
September 23, 2026 at 16:06 UTC
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
By [email protected] (The Hacker News)
AI Summary
CERT Polska detailed 'MikroTrick,' a chained exploit combining an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in RouterOS login (CVE-2026-86060), enabling full administrative takeover of internet-exposed MikroTik routers without credentials or SSH keys. Attack logs confirm real-world exploitation is already occurring. Network defenders managing MikroTik RouterOS devices should patch immediately given the no-auth, full-control impact.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →