INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

MikroTrick Attack Chain Exploited via MikroTik RouterOS

| 2026-09-24 18:16 HIGH HIGH
Executive Summary AI-generated
The incident involves a critical flaw in MikroTik RouterOS software that allows an attacker to gain full administrative access without a password, SSH key or successful authentication. The vulnerability is combined with another CVE-2026-67279, which enables an unauthenticated client to create a session channel and supply login with an attacker-controlled policy mask. Attack logs collected from the MikroTik forum and Reddit show a consistent source IP repeatedly attempting this exact sequence, resulting in several cases of successful exploitation. The incident highlights the importance of timely patching and coordinated disclosure by CERT Polska, which published an advisory alongside MikroTik's release.
Technical Mitigations AI-generated
* Implement input validation and sanitization for usernames, especially when used as command-line arguments to the login process, to prevent attackers from sending malicious options that can bypass authentication. * Use secure coding practices, such as validating privilege levels before passing them to the login process, to prevent attackers from exploiting vulnerabilities like CVE-2026-67279 by setting the privilege mask too high or using a specially crafted username. * Regularly update and patch RouterOS versions to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Use secure authentication mechanisms, such as multi-factor authentication (MFA) or password policies with strong requirements, to prevent attackers from gaining unauthorized access even if they successfully exploit one of the identified vulnerabilities.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060 CVE-2026-67279CVE-2026-67279 CVE-2026-67276CVE-2026-67276
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎as early as September 2
Threat actors used a vulnerability in MikroTik RouterOS to exploit an AI-powered attack chain targeting the router.
attribution CERT Polska
‎September 3, 2026
MikroTik pushed out patches for several RouterOS issues on September 3, 2026.
organisation MikroTik
organisation RouterOS
organisation CVE-2026
infrastructure 5.5-cyber
infrastructure 5.6-sol
infrastructure 40 virtual devices
organisation SSH
organisation CVE
organisation SecurityAffairs
infrastructure 2 descriptor
‎September 4
Threat actors used a vulnerability exploit in MikroTik RouterOS to target 24 different versions of the network device.
general_metric 24 different versions
observable npratley.net
‎September 5
MikroTik's RouterOS was vulnerable to the "-2" file descriptor trick.
attribution CERT Polska
‎September 10
Threat actors used a known exploit of CVE-2026-86060 to target MikroTik routers on September 10.
target_region United States
industry Government
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-86060
‎September 24, 2026
Threat actors used AI to uncover a MikroTrick attack chain in a MikroTik router.
organisation MikroTrick
‎2026/09/24
Threat actors used a previously unknown vulnerability in MikroTik RouterOS to exploit and gain unauthorized access.
‎2026/09/24
MikroTrick Chain attacks exploit a vulnerability in MikroTik RouterOS that allows attackers to take over routers without a password or SSH key by chaining two known vulnerabilities: CVE-2026-67279 (SSH state-machine flaw) and CVE-2026-86060 (argument-injection bug).
organisation CVE-2026
organisation CVE-2026-86060
organisation MikroTrick
organisation SSH
organisation MikroTik
organisation RouterOS
infrastructure 2 descriptor
organisation IP
organisation SSH Key
organisation RouterOS 6.49.21
data_breach 2 September
organisation the Chain Works
organisation /nova/bin/login
organisation Pre-Patch Exploitation
Tactical Metrics
Metrics
infrastructure
‎5.5-cyber
Software Version
Metrics
infrastructure
‎5.6-sol
Software Version
Metrics
infrastructure
40
Virtual Devices
Metrics
infrastructure
2
Descriptor
Metrics
data_breach
2
September
Intelligence Sources