MikroTrick: Inside the RouterOS Takeover Chain
Reported exploitedMikroTik RouterOSOur summary
Attackers exploited a chain in MikroTik RouterOS, dubbed MikroTrick, to take over exposed routers without credentials before fixes were publicly disclosed. CVE-2026-67279 bypasses SSH authentication after rekeying, while CVE-2026-86060 can turn a crafted username into a trusted administrative identity on vulnerable RouterOS 7.x builds. Update to 6.49.21, 7.23.4, 7.24.2, or later, and investigate routers for persistent privileged accounts, scripts, and scheduled tasks because patching alone does not remove an existing compromise.
Bishop Fox publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.