HackerFeeds

CyberSecurity News

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News
· September 23, 2026

AI summary

Attackers can gain full administrative control of MikroTik routers exposed to the internet without needing a password, SSH key, or completed authentication. This is made possible by chaining two vulnerabilities in RouterOS SSH, specifically a state-machine flaw and an argument-injection bug in the login process. These vulnerabilities are referred to as MikroTrick by CERT Polska. The flaws are identified as CVE-2026-67279 and CVE-2026-86060. Attack logs indicate that exploitation of these vulnerabilities has been occurring.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.