Tips

/

feb 16, 2025

CISA Flags Actively Exploited MikroTik RouterOS Flaws as MikroTrick Attacks Continue

CISA added two actively exploited MikroTik RouterOS CVEs to its KEV catalog as CERT Polska confirms active MikroTrick SSH takeover attacks.

/

AUTHOR

Jeff Dyer

CISA has added two MikroTik RouterOS vulnerabilities, CVE-2026-86060 and CVE-2026-67277, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of real-world exploitation.

Separately, CERT Polska has confirmed active exploitation of the MikroTrick attack chain, which combines CVE-2026-67276, an SSH authentication-bypass vulnerability, with CVE-2026-86060, an SSH privilege-manipulation vulnerability. Together, these flaws can allow attackers to obtain full administrative control of vulnerable RouterOS devices when SSH is accessible from public networks.

Organizations operating affected MikroTik devices should update immediately, restrict management exposure, and investigate devices that were vulnerable and exposed before remediation for evidence of compromise.

Understanding the MikroTik RouterOS Risk

On September 10, CISA added CVE-2026-86060 and CVE-2026-67277 to the KEV catalog, increasing the urgency for organizations operating affected MikroTik devices across internet edges, branch offices, remote sites, and managed customer environments.

An important distinction is that these two KEV entries are not the two vulnerabilities that comprise the MikroTrick takeover chain.

CERT Polska identified six RouterOS vulnerabilities during its research. MikroTrick specifically combines:

CVE-2026-67276 - SSH Authentication Bypass: Improper verification of RSA public keys can, under the vulnerability's prerequisites, allow an attacker to authenticate without possessing the corresponding private key.

CVE-2026-86060 - SSH Privilege Manipulation: Improper handling of specially crafted usernames in the SSH login process can elevate the resulting session to full administrative privileges.

CERT Polska has confirmed exploitation of this combination against RouterOS devices with SSH exposed to public networks.

CVE-2026-67277 is separate from MikroTrick. It affects the RouterOS bandwidth-test service. An unauthenticated connection can improperly reach a state that should require authentication and, when combined with additional implementation flaws, can result in kernel-memory leakage or a remote denial-of-service condition that restarts the system.

Why Patching Alone May Not Be Enough

A compromised router occupies a highly trusted position within the network. Administrative access can allow an attacker to modify users, scripts, scheduled tasks, proxy settings, tunnels, firewall rules, and other configuration.

Depending on the device's role and the attacker's actions, that access could potentially support persistence, traffic observation or redirection, or access toward other systems.

CERT Polska reports that successful attacks it observed, including activity associated with creation of a highly privileged ops account, originated from 82.192.72.4 and had occurred since at least September 2. Researchers also observed 103.102.31.18 in exploitation attempts. However, organizations should not assume that the absence of these indicators means a device was never compromised.

Fixed RouterOS releases include a mechanism that scans the configuration at startup for selected known signs of unauthorized changes. When recognized suspicious entries are detected, RouterOS disables them, generates a critical log message, and sets the Flagged warning. CERT Polska also observed artifacts involving the username -2 and creation of the privileged ops account.

A Flagged device or these artifacts should trigger immediate investigation. But a device that is not Flagged should not automatically be considered clean. The mechanism detects selected known traces of compromise, not every possible form of unauthorized activity.

Installing a fixed release closes the observed exploit path, but it cannot reverse malicious activity that may have occurred before the upgrade.

Immediate Remediation and Investigation

MikroTik has released fixes in:

  • RouterOS 7.24.2 - Stable

  • RouterOS 7.23.4 - Long-term

  • RouterOS 6.49.21 - Long-term

  • RouterOS 7.25 beta 3 - Beta

Organizations should deploy the appropriate fixed release for the device's supported RouterOS branch, or a newer release containing the applicable fixes. CERT Polska has confirmed that the released patches prevent the attacks it observed.

Administrators should also ensure that SSH is not exposed to untrusted networks. MikroTik's default configuration blocks SSH from the internet, but organizations that have opened the service should restrict management access to trusted IP addresses or, preferably, use a secure VPN such as WireGuard instead of exposing management ports directly.

After upgrading, verify the running RouterOS version and review the device for:

  • The Flagged warning

  • Unfamiliar users, particularly the privileged ops account

  • Log activity involving -2

  • Unknown scripts or scheduler tasks

  • Unexpected proxy servers or tunnels

  • Other unexplained configuration changes

Where available, correlate these findings with authentication, DNS, network-flow, firewall, endpoint, and SIEM telemetry to determine whether suspicious activity extended beyond the router.

If evidence supports compromise, treat the situation as a security incident rather than simply a patching exercise. Preserve relevant evidence where incident-response requirements call for it and recover the device using a trusted, verified configuration on a fixed RouterOS release.

Organizations should avoid blindly restoring a full configuration backup that may contain attacker-created changes. Credentials, keys, certificates, and other secrets potentially exposed through the compromised device should also be evaluated for rotation.

Where BackBox Fits

This incident illustrates why network vulnerability management involves more than identifying a CVE and installing firmware.

Network teams must know which devices they manage, understand their software versions, maintain trusted configuration backups, execute approved upgrades consistently, validate post-change state, and retain the ability to recover network infrastructure safely.

BackBox provides network automation capabilities spanning backup and recovery, OS upgrades, vulnerability remediation, and configuration compliance across multi-vendor network and security infrastructure.

Applied to the RouterOS response, BackBox can help organizations operationalize controlled remediation workflows across managed network-device estates, maintain trusted configuration backups, execute approved software upgrades consistently, and validate configuration state after changes.

BackBox automation does not, by itself, determine whether a MikroTik device was compromised by MikroTrick. That determination should rely on RouterOS evidence, logs, the Flagged warning, configuration review, and other relevant security and incident-response telemetry.

The distinction is important because automation should support both remediation and safe recovery. If compromise is suspected, teams should validate privileged accounts and automation artifacts and ensure that any configuration used for recovery is known to be trustworthy before returning the device to service.

Automation can make remediation and recovery more consistent. It should never automate the reintroduction of an attacker's changes.

What RouterOS Operators Should Do Now

CISA has added two MikroTik RouterOS vulnerabilities, CVE-2026-86060 and CVE-2026-67277, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of real-world exploitation.

Separately, CERT Polska has confirmed active exploitation of the MikroTrick attack chain, which combines CVE-2026-67276, an SSH authentication-bypass vulnerability, with CVE-2026-86060, an SSH privilege-manipulation vulnerability. Together, these flaws can allow attackers to obtain full administrative control of vulnerable RouterOS devices when SSH is accessible from public networks.

Organizations operating affected MikroTik devices should update immediately, restrict management exposure, and investigate devices that were vulnerable and exposed before remediation for evidence of compromise.

Contact Integralty to schedule a BackBox demo.

info@integralty.com | (855) 514-5855 | integralty.com

/

BLOG

Other insights