[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBBH6pxN7kmi5NvU3Iq3rDu8gnER07W-eQrafbX8OKBE":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"5e0f64f3-65fe-4aa4-8088-de90d0e460d0","MikroTik Patches Critical Flaws Chained to Hack Routers","mikrotik-patches-critical-flaws-chained-to-hack-routers-4fcc36","Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.","MikroTik has released patches for six vulnerabilities in its RouterOS, with two of them, dubbed MikroTrick, being actively exploited in the wild. These chained vulnerabilities allow attackers to bypass authentication, manipulate SSH sessions, and gain full control of devices accessible from public networks. CERT Poland warns that exploitation has been ongoing since at least September 2, with attacks originating from specific IP addresses and creating a user account named 'ops'.","MikroTik patches six critical RouterOS vulnerabilities, two of which are actively exploited.","Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited. The exploited flaws, dubbed MikroTrick, allow attackers to bypass authentication and take over devices, CERT Poland warns. In a scarce advisory, MikroTik warns of the identified security defects, recommends immediate patching, and directs users to CERT Poland’s advisory for additional information. “This is an important security update. Most configurations are not at risk,” MikroTik says. It also recommends blocking SSH access from untrusted sources, noting that compromised devices will have a “Flagged” entry in the log section. CERT Poland, meanwhile, says it has received confirmation that two of the resolved vulnerabilities have been chained together to compromise devices. “We now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control of devices whose SSH service is accessible from public networks. According to the information we have, updating to the latest version prevents these attacks,” CERT Poland notes.Advertisement. Scroll to continue reading. It highlights three vulnerabilities: CVE-2026-67276 (CVSS score of 9.2), an SSH authentication bypass bug; CVE-2026-86060 (CVSS score of 9.2), an SSH session privilege manipulation issue; and CVE-2026-67277 (CVSS score of 8.8), a memory disclosure and denial-of-service weakness. CERT Poland says hackers have been chaining the MikroTrick bugs since at least September 2, creating an account named ‘ops’. The attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifacts indicates an attempt to exploit the vulnerabilities and must be investigated immediately; at the same time, the absence of the traces mentioned above does not rule out unauthorized activity,” CERT Poland notes. Users are advised to update their MikroTik routers to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible. The updates also resolve CVE-2026-67278 (enables TLS server impersonation), CVE-2026-67279 (allows unauthenticated attackers to tamper with files, including configuration files), and CVE-2026-67281 (allows attackers to disclose root-owned files, including configuration stores). The Shadowserver Foundation found more than 120,000 MikroTik devices with SSH accessible from the internet during a 24-hour scan window on September 5. Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation Related: Malicious Virtualizor Update Served via BGP Hijacking Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire HPE Patches Critical RCE Vulnerabilities in AOS-CXSangoma Switchvox Vulnerability Exploited in the Wild12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverVMware Workstation and Fusion Updates Patch Critical VulnerabilityGoogle Patches 6th Chrome Zero-Day of 2026Manchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalHiddenLayer Raises $100 Million for AI Runtime Security153 Million Driver License Images Offered on Dark Web Latest News Mathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitOpenAI Agents Hijack Another Victim WebsiteAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fmikrotik-patches-critical-flaws-chained-to-hack-routers\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-09-08T11:15:00+00:00","2026-09-08T12:00:14.498934+00:00",9,[18,21,24],{"name":19,"type":20},"RouterOS","product",{"name":22,"type":23},"MikroTik","vendor",{"name":25,"type":26},"MikroTrick","campaign","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,35,40,45],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55,57,61,64],{"type":52,"value":53,"context":54},"ip","82.192.72.4","Source IP address of MikroTrick exploitation.",{"type":52,"value":56,"context":54},"103.102.31.18",{"type":58,"value":59,"context":60},"mitre_attack","T1078","Creation of accounts ('ops') by attackers.",{"type":58,"value":62,"context":63},"T1110.004","SSH authentication bypass vulnerability.",{"type":58,"value":65,"context":66},"T1071.001","SSH service accessible from public networks."]