MikroTik router flaws allow takeover without a password
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.
Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.
Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.
A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.
Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276, is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process.
Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.
SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.
CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix.
How to stay safe
MikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik. The update option should be available under Check for updates.
You should also remove public access to the router’s management services. Make sure that SSH is not accessible from untrusted networks. If remote administration is necessary, limit access to known IP addresses.
Remote management should be the exception, not the default. MikroTrick demonstrates that a strong password alone cannot protect a device from an authentication-bypass vulnerability.
MikroTik has added a detection mechanism that scans the configuration at startup for selected signs of unauthorized changes. If it finds any, RouterOS disables the recognized suspicious entries and sets the device’s Flagged status to Yes. Administrators can check this with /system/device-mode/print
.
RouterOS restricts several potentially abusable functions while the device is flagged, but MikroTik stresses that the router’s full configuration still needs to be audited before the flag is cleared.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.