INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
MikroTrick Attack Chain Exploited via MikroTik RouterOS
| 2026-09-24 18:16 HIGH HIGHExecutive Summary AI-generated
The incident involves a critical flaw in MikroTik RouterOS software that allows an attacker to gain full administrative access without a password, SSH key or successful authentication. The vulnerability is combined with another CVE-2026-67279, which enables an unauthenticated client to create a session channel and supply login with an attacker-controlled policy mask. Attack logs collected from the MikroTik forum and Reddit show a consistent source IP repeatedly attempting this exact sequence, resulting in several cases of successful exploitation. The incident highlights the importance of timely patching and coordinated disclosure by CERT Polska, which published an advisory alongside MikroTik's release.
Technical Mitigations AI-generated
* Implement input validation and sanitization for usernames, especially when used as command-line arguments to the login process, to prevent attackers from sending malicious options that can bypass authentication.
* Use secure coding practices, such as validating privilege levels before passing them to the login process, to prevent attackers from exploiting vulnerabilities like CVE-2026-67279 by setting the privilege mask too high or using a specially crafted username.
* Regularly update and patch RouterOS versions to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Use secure authentication mechanisms, such as multi-factor authentication (MFA) or password policies with strong requirements, to prevent attackers from gaining unauthorized access even if they successfully exploit one of the identified vulnerabilities.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060
CVE-2026-67279CVE-2026-67279
CVE-2026-67276CVE-2026-67276
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
as early as September 2
Threat actors used a vulnerability in MikroTik RouterOS to exploit an AI-powered attack chain targeting the router.
Click on any entity below to view its context and source!
attribution
CERT Polska
CERT Polska says logs matching this pattern appeared on the MikroTik forum as early as September 2, one day before the patches became available, and the team believes the chain was exploited before MikroTik released the fixes.
September 3, 2026
MikroTik pushed out patches for several RouterOS issues on September 3, 2026.
Click on any entity below to view its context and source!
organisation
MikroTik
MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed.
organisation
RouterOS
MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed.
organisation
CVE-2026
“CVE-2026-67279 allowed an unauthenticated client to create a
session
channel, while CVE-2026-86060 allowed it to supply
login
with an attacker-controlled policy mask.”
infrastructure
5.5-cyber
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
infrastructure
5.6-sol
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
infrastructure
40 virtual devices
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
organisation
SSH
Combined with another vulnerability, CVE-2026-67279, the two flaws could give an attacker full administrative access without a password, SSH key, or successful authentication.
organisation
CVE
anywhere in your infrastructure, particularly on devices exposed to SSH from the internet, patching isn’t optional at this point and it isn’t really about the CVE numbers either.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, MikroTik)
infrastructure
2 descriptor
The login process treats
-2
as an option that points to file descriptor 2, which is connected to the same terminal channel controlled by the attacker.
September 4
Threat actors used a vulnerability exploit in MikroTik RouterOS to target 24 different versions of the network device.
Click on any entity below to view its context and source!
general_metric
24 different versions
In this case, a public analysis on npratley.net identified the key SSH changes by September 4, less than 24 hours after the patch.
observable
npratley.net
In this case, a public analysis on npratley.net identified the key SSH changes by September 4, less than 24 hours after the patch.
September 5
MikroTik's RouterOS was vulnerable to the "-2" file descriptor trick.
Click on any entity below to view its context and source!
attribution
CERT Polska
As
previously reported
, CERT Polska warned on September 5 that attackers were using RouterOS flaws to take control of devices whose SSH service was reachable from public networks.
September 10
Threat actors used a known exploit of CVE-2026-86060 to target MikroTik routers on September 10.
Click on any entity below to view its context and source!
target_region
United States
CISA added two of these CVEs to its Known Exploited Vulnerabilities catalog on September 10, with a three day remediation deadline, which tells you how seriously the US government is treating the gap between disclosure and real-world exploitation here.
industry
Government
CISA added two of these CVEs to its Known Exploited Vulnerabilities catalog on September 10, with a three day remediation deadline, which tells you how seriously the US government is treating the gap between disclosure and real-world exploitation here.
attribution
Known Exploited
CISA added two of these CVEs to its Known Exploited Vulnerabilities catalog on September 10, with a three day remediation deadline, which tells you how seriously the US government is treating the gap between disclosure and real-world exploitation here.
CISA
added
CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, independently confirming active exploitation of the argument-injection flaw.
tactic
T1588.006 - Vulnerabilities
CISA added two of these CVEs to its Known Exploited Vulnerabilities catalog on September 10, with a three day remediation deadline, which tells you how seriously the US government is treating the gap between disclosure and real-world exploitation here.
CISA
added
CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, independently confirming active exploitation of the argument-injection flaw.
vulnerability
CVE-2026-86060
CISA
added
CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, independently confirming active exploitation of the argument-injection flaw.
September 24, 2026
Threat actors used AI to uncover a MikroTrick attack chain in a MikroTik router.
Click on any entity below to view its context and source!
organisation
MikroTrick
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
Pierluigi Paganini
September 24, 2026
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access.
2026/09/24
Threat actors used a previously unknown vulnerability in MikroTik RouterOS to exploit and gain unauthorized access.
2026/09/24
MikroTrick Chain attacks exploit a vulnerability in MikroTik RouterOS that allows attackers to take over routers without a password or SSH key by chaining two known vulnerabilities: CVE-2026-67279 (SSH state-machine flaw) and CVE-2026-86060 (argument-injection bug).
Click on any entity below to view its context and source!
organisation
CVE-2026
CVE-2026-86060 turns that access into full administrative control.
organisation
CVE-2026-86060
The MikroTrick chain is CVE-2026-67279 combined with CVE-2026-86060.
organisation
MikroTrick
The MikroTrick chain is CVE-2026-67279 combined with CVE-2026-86060.
organisation
SSH
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
organisation
MikroTik
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
organisation
RouterOS
Every finding was verified against real RouterOS systems.
infrastructure
2 descriptor
The login program treats this as an instruction to read its identity and privilege level from file descriptor 2, which points to the terminal the SSH session created.
organisation
IP
IP
: 103.102.31.18 (used in exploitation attempts)
Administrators should also check for unknown users, scripts, scheduler entries, tunnels, proxies, unexpected .rif diagnostic files, or unexplained fetch activity.
organisation
SSH Key
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key.
organisation
RouterOS 6.49.21
Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
data_breach
2 September
Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
organisation
the Chain Works
How the Chain Works
SSH requires three steps in order: it establishes an encrypted connection, authenticates the user, and only then lets the client open a session and run commands.
organisation
/nova/bin/login
RouterOS launches a login program (/nova/bin/login) that receives the username and a privilege level from the SSH daemon as command-line arguments, without checking the username first.
organisation
Pre-Patch Exploitation
Evidence of Pre-Patch Exploitation
The chain leaves a distinctive trace in device logs: a failed login attempt for user -2.
Tactical Metrics
Metrics
infrastructure
5.5-cyber
Software Version
Click for context!
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
Metrics
infrastructure
5.6-sol
Software Version
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
Metrics
infrastructure
40
Virtual Devices
CERT Polska used GPT-5.5-cyber and GPT-5.6-sol through OpenAI’s GTAC program, together with locally hosted open-weight models, to build an isolated lab with 40 virtual RouterOS devices covering 24 different versions.
Metrics
infrastructure
2
Descriptor
The login process treats
-2
as an option that points to file descriptor 2, which is connected to the same terminal channel controlled by the attacker.
The login program treats this as an instruction to read its identity and privilege level from file descriptor 2, which points to the terminal the SSH session created.
Metrics
data_breach
2
September
Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
Intelligence Sources
The Hacker News
2026-09-23
Security Affairs
2026-09-24
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-25T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
organisation
Identified Entity
SSH
entity
8x
timeline
Temporal Reference
September 10
date
7x
attribution
Attributing Entity
Known Exploited
authority
3x
vulnerability
Exploited CVE
CVE-2026-86060
cve
2x
infrastructure
Software Version
5.5-cyber
version
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
United States
country
industry
Targeted Sector
Government
sector
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
infrastructure
Virtual Devices
40
virtual devices
general metric
Different Versions
24
different versions
infrastructure
Descriptor
2
descriptor
data breach
September
2
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.