Attackers Are Hijacking Internet-Exposed MikroTik Routers Through Unauthenticated SSH, CERT Polska Warns

Attackers Are Hijacking Internet-Exposed MikroTik Routers Through Unauthenticated SSH, CERT Polska Warns

Attackers Are Actively Hijacking MikroTik Routers via Unauthenticated SSH Flaw Chain

CERT Polska, the national CSIRT operated by NASK, has warned that attackers are actively exploiting internet-exposed MikroTik RouterOS devices, gaining full unauthenticated administrative control through their SSH services. According to the advisory, the vulnerability chain being exploited has been nicknamed "MikroTrick" by researchers, and it combines two separate flaws to bypass authentication entirely. CERT Polska says the attack activity can be traced back to at least September 2, 2026, a timeline that appears to predate or closely coincide with the release of vendor patches.

Security researchers note that the situation is especially concerning for routers that have been left internet-facing and infrequently maintained, since these devices may already be compromised without any obvious signs to their owners.

How the "MikroTrick" Exploit Chain Works

CERT Polska's disclosure describes an exploit chain resting on two critical vulnerabilities. The first, tracked as CVE-2026-67276, is an SSH authentication bypass stemming from a flaw in RSA public key verification, carrying a CVSS score of 9.2. The second, CVE-2026-86060, is a session privilege escalation issue triggered by a specially crafted username, also rated CVSS 9.2. When chained together, these two flaws allow an attacker to obtain full unauthenticated administrative access to a device's SSH service.

A related but separate issue, CVE-2026-67277, is also mentioned in the disclosure. This flaw can cause memory disclosure or a crash via the bandwidth-test tool and carries a CVSS score of 8.8. CERT Polska's disclosure covers six vulnerabilities in total, with two of them — the pair forming the MikroTrick chain — confirmed as under active exploitation in the wild.

Attack Infrastructure and Observed Activity

Malicious traffic tied to this campaign has been linked to two IP addresses: 82.192.72.4, observed since at least September 2, and 103.102.31.18. Some reporting on the incident describes failed login attempts using a username formatted as "-2", with successful compromises logged in a similar pattern (ssh:-2@<IP>). A recurring indicator flagged in coverage is the creation of a rogue administrative account named "ops," which several sources point to as a sign that a device has already been compromised.

It is worth noting that attribution details around the attacking infrastructure, including confirmed actor identity, are still described as preliminary in the available reporting.

Patches and Affected Versions

MikroTik has published fixed RouterOS versions in response to the disclosure: 6.49.21, 7.23.4, 7.23.5, 7.24.2, and 7.25beta3. Notably, version 7.23.5 was issued shortly after 7.23.4 to correct an IPv6 DHCP regression that the earlier patch had introduced. Both CERT Polska and MikroTik are urging immediate updates for any internet-facing devices running affected versions.

What Router Owners Should Do Now

Guidance emerging from CERT Polska and corroborating security coverage converges on a consistent set of recommendations for RouterOS administrators:

  • Immediately update to the latest patched RouterOS version available for your device
  • Disable exposed SSH, WWW, WWW-SSL, and bandwidth-test services until the update has been applied
  • Audit device logs for indicators of compromise, including unusual usernames and unexpected new accounts
  • Avoid restoring configuration backups from a device that may have been compromised
  • Treat the absence of known indicators of compromise as inconclusive rather than proof that a device is safe

CERT Polska has cautioned that its detection markers should be treated as an indication rather than definitive proof of compromise, and that undisclosed or unknown vulnerabilities beyond the six reported cannot be ruled out.

Open Questions and Unverified Claims

Several aspects of this incident remain unconfirmed as of this writing. The total number of affected devices and the identity of the attackers have not been established by CERT Polska or MikroTik in public statements. A recurring point raised in secondary coverage is that whether this campaign truly constitutes a zero-day attack remains ambiguous, given the apparent overlap between the patch release timeline and the earliest observed exploitation activity.

CERT Polska's disclosure references the use of AI-assisted vulnerability research tools, described as GPT-5.5-cyber and GPT-5.6-sol, operating under what the agency calls its GTAC program, though details of this methodology are limited in public reporting. Researchers have said they are withholding proof-of-concept exploit code under responsible disclosure practices, though multiple sources suggest that public release of such code could be imminent, which would likely broaden the pool of attackers capable of exploiting unpatched devices.

More Tech articles · CuencaLife home