SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityMikroTikRouterOS

Mikrotik routeros: mikrotrick targets exposed routers

Three RouterOS flaws are being exploited, especially where SSH is exposed. Fixed versions and checks for administrators.

By Soclyde Team

A technician updates a router in a small-business equipment room

In summary

  • CVE-2026-67276 and CVE-2026-86060 can be chained to take over a RouterOS device exposed through SSH.
  • CVE-2026-67277 affects bandwidth-test and can disclose memory or restart the device.
  • Update RouterOS, close public management access and review logs and configuration.

Explore next

Soclyde resources

Article contents

CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 affecting MikroTik RouterOS are the subject of active-exploitation reports. The chain nicknamed MikroTrick is especially concerning when a router’s SSH service is reachable from the Internet.

MikroTik published fixed releases on September 3, 2026 and says typical home configurations are not exposed in the same way. For small businesses, the priority is to check real exposure, update and look for takeover evidence.

The three vulnerabilities

CVE-2026-67276 concerns RSA-key validation in the SSH path. CVE-2026-86060 enables session manipulation and privilege escalation with a specially crafted username. Together they can lead to administrator access when SSH is exposed.

CVE-2026-67277 affects the bandwidth-test service and may disclose memory or trigger a remote restart. Exact exposure depends on the enabled service and router configuration.

The exploitation signal

CERT.pl and Canada’s Cyber Centre describe attacks against Internet-accessible devices, while BleepingComputer reports the SSH chain. The sources do not say that every MikroTik router was taken over.

That distinction matters: a router protected by default filtering has a different exposure from a device administrable from any address.

Fixing and reducing exposure

MikroTik lists fixes in 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. Check the installed channel, update to a supported release and close SSH to untrusted networks; use a VPN or allowlist for administration.

Disable unused management services and inventory forgotten routers in small offices and remote sites. An isolated update does not fix ongoing public exposure.

Looking for evidence

After updating, check the Flagged state, users, scripts, scheduled tasks and rules no one recognises. Review SSH connections, configuration changes and unusual source addresses before clearing logs.

If takeover is plausible, isolate the device, export evidence and rotate passwords and secrets that could have been reachable from the router.

The Soclyde connection

Soclyde does not update RouterOS or confirm router integrity. It can help renew administrator access and service secrets by generating unique values in local-first encrypted vaults.

That avoids passwords copied into troubleshooting notes, but it does not replace network segmentation or device review.

Key takeaways

MikroTrick combines RouterOS flaws that particularly expose routers with SSH open to the Internet. Update, close public access, check Flagged and configuration, then rotate secrets when needed. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Which versions fix MikroTrick?

MikroTik lists fixes in 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. Check your release channel and install a newer supported version.

Are all MikroTik routers compromised?

No. Risk depends on exposure, especially SSH exposure, and configuration. Sources report exploitation of Internet-accessible devices, not universal compromise.

What should be checked after updating?

Look for the Flagged state, unknown users, scripts and rules, then review SSH access and rotate passwords if takeover is plausible.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading