MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
What happened
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Why it matters
The proceeding may create legal precedent, financial exposure or operating constraints for Regulation.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- The Hacker NewsPrimary source · Supports · EN · 100%MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key ↗
Claims
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
Market move following event
Market reaction is not yet available for this asset and time window.