MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Reported exploitedRouterOSOur summary
Attackers have exploited the MikroTrick chain, combining CVE-2026-67279 and CVE-2026-86060 to gain administrator control of Internet-exposed MikroTik RouterOS devices without credentials. MikroTik fixed the flaws in RouterOS 6.49.21, 7.23.4, and 7.24.2, but organizations should also investigate systems for signs of prior compromise, including SSH logins using -2 and unknown ops accounts. Exposed SSH services face the greatest risk; compromised routers should be isolated, reset, rebuilt from trusted configurations, and have credentials rotated.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.