CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 affecting MikroTik RouterOS are the subject of active-exploitation reports. The chain nicknamed MikroTrick is especially concerning when a router’s SSH service is reachable from the Internet.
MikroTik published fixed releases on September 3, 2026 and says typical home configurations are not exposed in the same way. For small businesses, the priority is to check real exposure, update and look for takeover evidence.
The three vulnerabilities
CVE-2026-67276 concerns RSA-key validation in the SSH path. CVE-2026-86060 enables session manipulation and privilege escalation with a specially crafted username. Together they can lead to administrator access when SSH is exposed.
CVE-2026-67277 affects the bandwidth-test service and may disclose memory or trigger a remote restart. Exact exposure depends on the enabled service and router configuration.
The exploitation signal
CERT.pl and Canada’s Cyber Centre describe attacks against Internet-accessible devices, while BleepingComputer reports the SSH chain. The sources do not say that every MikroTik router was taken over.
That distinction matters: a router protected by default filtering has a different exposure from a device administrable from any address.
Fixing and reducing exposure
MikroTik lists fixes in 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. Check the installed channel, update to a supported release and close SSH to untrusted networks; use a VPN or allowlist for administration.
Disable unused management services and inventory forgotten routers in small offices and remote sites. An isolated update does not fix ongoing public exposure.
Looking for evidence
After updating, check the Flagged state, users, scripts, scheduled tasks and rules no one recognises. Review SSH connections, configuration changes and unusual source addresses before clearing logs.
If takeover is plausible, isolate the device, export evidence and rotate passwords and secrets that could have been reachable from the router.
The Soclyde connection
Soclyde does not update RouterOS or confirm router integrity. It can help renew administrator access and service secrets by generating unique values in local-first encrypted vaults.
That avoids passwords copied into troubleshooting notes, but it does not replace network segmentation or device review.
Key takeaways
MikroTrick combines RouterOS flaws that particularly expose routers with SSH open to the Internet. Update, close public access, check Flagged and configuration, then rotate secrets when needed. Read the secure password generator guide or contact Soclyde.



