negativeSYS.SOURCE: The Hacker News• 2026-09-23T21:36:41+05:30
MikroTrick Chain Exploits SSH Vulnerabilities to Compromise MikroTik Routers Without Authentication
A chained vulnerability in MikroTik RouterOS allows attackers to gain full administrative control of exposed routers without authentication by exploiting CVE-2026-67279 and CVE-2026-86060. Administrators are advised to apply patches and check for indicators of compromise like the -2 username and ops account creation.
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
*** END OF TRANSMISSION ***