MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
- ID
- 27817
- Status
- summarized
- Published
- 24 Sep 2026, 12:06 AM
- Fetched
- 24 Sep 2026, 2:16 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 24 Sep 2026, 2:17 AM
- Tags
- Audience
- developerssaas_founders
What happened
Two MikroTik RouterOS SSH vulnerabilities chained together as 'MikroTrick' (CVE-2026-67279 and CVE-2026-86060) let attackers gain full admin control of internet-exposed routers with no password or SSH key. The first flaw skips authentication by triggering SSH key renegotiation during the auth phase; the second exploits argument injection where sending '-2' as the username tricks the login program into reading attacker-controlled identity and privilege level from the terminal. Patches shipped in RouterOS 6.49.21, 7.23.4, and 7.24.2, with attack logs dating to at least September 2.
Why it matters
MikroTik routers are ubiquitous in Malaysian SMEs, offices, and small ISPs. If you operate any MikroTik device with SSH reachable from the public internet, patch immediately to RouterOS 7.24.2 (or 6.49.21 / 7.23.4 at minimum) and disable public SSH access if not needed. Unpatched devices can be fully compromised with zero credentials, turning them into pivoting points for internal network attacks.
Discussion angle
How many Malaysian startups and SMEs run MikroTik routers with default or exposed SSH? This is a practical moment to audit office and cloud-adjacent network gear, since the exploit requires no credentials at all and MikroTik is the default choice for cost-conscious Malaysian businesses.