CVE Tools

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker NewsBy The Hacker News

Reported exploitedRouterOS

Our summary

Attackers have exploited the MikroTrick chain, combining CVE-2026-67279 and CVE-2026-86060 to gain administrator control of Internet-exposed MikroTik RouterOS devices without credentials. MikroTik fixed the flaws in RouterOS 6.49.21, 7.23.4, and 7.24.2, but organizations should also investigate systems for signs of prior compromise, including SSH logins using -2 and unknown ops accounts. Exposed SSH services face the greatest risk; compromised routers should be isolated, reset, rebuilt from trusted configurations, and have credentials rotated.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store