Home / Sep 24, 2026 / Story
0
#6 The Hacker News general September 23, 2026 at 16:06 UTC

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

By [email protected] (The Hacker News)

AI Summary

CERT Polska detailed 'MikroTrick,' a chained exploit combining an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in RouterOS login (CVE-2026-86060), enabling full administrative takeover of internet-exposed MikroTik routers without credentials or SSH keys. Attack logs confirm real-world exploitation is already occurring. Network defenders managing MikroTik RouterOS devices should patch immediately given the no-auth, full-control impact.

Relevance score: 85.0/100

# More from September 24