MikroTik Routers Under Active Attack: Patch RouterOS Now
CERT Polska and CISA say attackers are chaining RouterOS flaws to seize control of internet-exposed MikroTik routers without any login credentials.

Attackers are actively hijacking internet-exposed MikroTik routers by chaining a set of RouterOS vulnerabilities that Polish national CERT researchers have nicknamed "MikroTrick," and the U.S. Cybersecurity and Infrastructure Security Agency has now added three related CVEs to its Known Exploited Vulnerabilities (KEV) Catalog, most recently on September 25, 2026. MikroTik has shipped fixes, but says most of the technical detail is being withheld for now specifically so more administrators can patch before attackers who haven't already found the bugs can weaponize them.
- What: A chain of RouterOS vulnerabilities lets an unauthenticated attacker who can reach a device's SSH service take full administrative control.
- CVEs in CISA's KEV catalog: CVE-2026-86060 and CVE-2026-67277 (added September 10, 2026), and CVE-2026-67279 (added September 25, 2026), which CISA says can be chained to exploit CVE-2026-86060.
- Who found it: CERT Polska (CERT.pl), which published research on the "MikroTrick" campaign on September 5, 2026, and reported observing real attack traffic since at least September 2.
- Fixed in: RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) or later.
- Sign of compromise: CERT Polska says a successful attack typically creates a privileged account named "ops"; MikroTik's own tooling can flag devices it detects were compromised.
- Who's exposed: Any MikroTik router or switch running RouterOS with SSH, Winbox or other management services reachable from the public internet.
What happened: the "MikroTrick" RouterOS campaign
On September 5, 2026, CERT Polska published research describing a set of RouterOS vulnerabilities it collectively refers to by the campaign name "MikroTrick." The most serious of them allow an attacker with network access to a device's SSH service to bypass authentication entirely and, by chaining two flaws together, take full administrative control of the router without ever having valid credentials. CERT Polska reported it had already observed real attack traffic against internet-facing RouterOS devices, tracing exploitation attempts back to at least September 2, 2026, from specific IP addresses it published in its advisory.
MikroTik's own security advisory confirms it "found a security vulnerability in RouterOS and releases containing a fix have been published in all channels," calling it "an important security update" and adding that "most configurations are not at risk, but upgrading is highly recommended." Notably, the company says it is deliberately withholding detailed technical information for now, writing that it wants "to give time to update your systems" before publishing specifics that could otherwise hand attackers who haven't already reverse-engineered the bugs a ready-made blueprint.
The vulnerabilities behind MikroTrick
CERT Polska's research and CISA's KEV catalog together point to several distinct RouterOS bugs. Three currently carry confirmed CISA KEV listings:
| CVE | Issue | Added to CISA KEV |
|---|---|---|
| CVE-2026-86060 | Improper neutralization of argument delimiters lets an attacker alter the trusted RouterOS policy mask, escalating privileges. | September 10, 2026 |
| CVE-2026-67277 | Missing authentication in the bandwidth-test ("btest") service allows kernel memory disclosure and denial of service. | September 10, 2026 |
| CVE-2026-67279 | RouterOS's SSH service mishandles a client-requested rekey, letting an unauthenticated client open a session channel and issue commands — CISA notes this can be chained to exploit CVE-2026-86060 without any credentials at all. | September 25, 2026 |
CERT Polska's write-up also references a fourth flaw, CVE-2026-67276 — an SSH authentication bypass it rates 9.2 out of 10 in severity — as part of the same research disclosure, though as of publication that particular CVE does not yet carry its own CISA KEV listing. NVD's record for CVE-2026-67279 confirms the technical description: it is fixed in RouterOS 6.49.21, 7.23.4 and 7.24.2.
How the attack actually works
According to CERT Polska, the practical danger is that two of the RouterOS bugs can be combined by an attacker who can simply reach a device's SSH port over the internet — no username, password or prior access required. Once chained, the flaws let an attacker escalate to full administrative control of the router. CERT Polska says a successful compromise typically leaves behind a telltale sign: a newly created privileged user account named "ops," which administrators can look for directly in their device's user list as a quick compromise check.
MikroTik has built detection directly into RouterOS itself: according to the company's advisory, "RouterOS will check if your device has been compromised, and set it to 'Flagged' status if it is," with the result written to the device's system log. Administrators who see a critical log entry reporting a device as Flagged are directed to MikroTik's own documentation for remediation steps, and the company recommends inspecting configurations for unknown scripts or users even on devices that aren't flagged, since RouterOS's own detection isn't guaranteed to catch every case.
Why router vulnerabilities like this draw outsized concern
Routers occupy a different risk category than most other devices on a network, which is part of why security researchers and CISA treat unauthenticated router-takeover bugs with unusual urgency. Unlike a compromised laptop or phone, a compromised router sits in the path of every device behind it, and taking it over doesn't require tricking any individual person into clicking a link or opening a file — it only requires the device to be reachable. Large-scale router and IoT-device compromises have historically been used to build botnets capable of denial-of-service attacks, relay traffic to disguise the true source of other intrusions, or simply sit dormant as durable footholds inside networks that are rarely rebooted, patched or monitored as closely as a typical laptop or phone. CERT Polska's and CISA's advisories for MikroTrick don't specify what any given attacker's ultimate objective is, but the pattern of an unauthenticated, internet-reachable takeover of network infrastructure is the same shape that has driven previous large router-botnet incidents.
Who's actually exposed
MikroTik routers and switches run in a wide range of settings, from internet service providers and enterprise networks to small businesses and, in some markets, prosumer home setups — RouterOS powers everything from the compact hAP series up through carrier-grade routing hardware. The specific risk here applies to devices with SSH, Winbox, or other management interfaces exposed directly to the public internet rather than restricted to a local network or VPN. MikroTik's advisory frames this as the key mitigating factor, noting that "most configurations are not at risk" — the danger concentrates heavily on devices that have management access reachable from outside their own network, a configuration that's common on ISP-managed equipment and some self-hosted setups but isn't the RouterOS default.
Home users are less likely to be directly affected than network administrators, since most consumer routers — including MikroTik's own home-oriented lines — ship with management access closed to the internet by default, and the average household doesn't run RouterOS at all. Anyone unsure whether a router on their network is a MikroTik device can typically check the manufacturer name printed on the hardware itself or in the router's own admin login page; if it doesn't say MikroTik, this specific campaign doesn't apply, though keeping any router's firmware current and its admin panel closed to the open internet is sound practice regardless of brand.
How to check and patch a MikroTik device
| RouterOS branch | Fixed version | Where to check |
|---|---|---|
| Long-term (6.x) | 6.49.21 or later | WinBox/WebFig > System > Packages, or Check for Updates |
| Long-term (7.x) | 7.23.4 or later | WinBox/WebFig > System > Packages, or Check for Updates |
| Stable (7.x) | 7.24.2 or later | WinBox/WebFig > System > Packages, or Check for Updates |
Administrators can confirm their installed version from the RouterOS command line with /system package update print, or from WinBox/WebFig under System > Packages, and should update to whichever fixed release matches the branch they're already running rather than switching branches during a security response. Devices managed centrally through MikroTik's cloud tools can often have updates scheduled or pushed across a fleet at once, which is generally faster than checking each device individually when many are affected.
Beyond installing the update, MikroTik and CERT Polska's guidance both point to the same immediate step: check the device's system log for a critical entry indicating "Flagged" status, and separately check the user list for any unrecognized account — particularly one named "ops" — plus any scripts or scheduled tasks that weren't intentionally created. Restricting SSH, Winbox and other management services so they're reachable only from a trusted local network or VPN, rather than the open internet, removes the specific access path this campaign relies on, independent of whether a given device has already been patched.
Why the CISA listing matters beyond RouterOS itself
CISA doesn't add a vulnerability to its Known Exploited Vulnerabilities Catalog merely because it's severe — the listing specifically means the agency has confirmed active, real-world exploitation, as distinct from the much larger set of bugs that are serious in theory but not yet seen being used in the wild. Under Binding Operational Directive 26-04, each KEV addition carries a remediation deadline for federal agencies scaled to risk; CVE-2026-67279's three-day window, running from September 25 to September 28, reflects how directly it can be chained into a fully unauthenticated compromise of an internet-facing device. Federal deadlines don't bind private businesses or home users, but security teams broadly treat a fresh KEV addition the same way CISA intends it: as confirmation an update needs to happen now, not on the next routine maintenance cycle.
What makes the September 25 addition notable is its timing relative to the rest of the campaign. CERT Polska's initial disclosure and MikroTik's first fixes both landed in early September, and the two most severe chained flaws were already KEV-listed by September 10. CVE-2026-67279 being added two weeks later, specifically flagged by CISA as a way to reach CVE-2026-86060 without any credentials at all, indicates researchers and defenders kept finding additional paths into the same underlying weakness even after the initial round of patches shipped — a reminder that closing one exploitation route in a vulnerability chain doesn't necessarily close all of them, and that devices patched against the first wave of MikroTrick disclosures still needed a second update to be fully covered.
Protecting the rest of your network
A compromised router sits in a uniquely dangerous position on a network — attackers who control it can potentially intercept or redirect traffic for every device behind it, not just the router itself, which is part of why RouterOS bugs that allow unauthenticated administrative takeover draw this level of urgency. That's a good prompt to double-check account-level protections elsewhere too: Pandromeda's guide to setting up an authenticator app for two-factor authentication covers adding a second layer of protection that a compromised network alone can't bypass, and our explainer on how to check whether your email or passwords have already been exposed in past breaches is a quick way to see whether unrelated credential leaks have separately put your accounts at risk.
What's next
MikroTik says it will publish additional technical detail on the underlying vulnerabilities "in due time," once enough administrators have had the chance to patch. CERT Polska's advisory remains open for updates as it continues tracking exploitation activity, and CISA's KEV catalog entry for CVE-2026-67279 carries a September 28, 2026 federal remediation deadline that has already passed as of publication, underscoring how quickly the agency expected this one to be addressed. Pandromeda will update this article if MikroTik, CERT Polska or CISA publish further detail on the scale of the campaign or additional affected CVEs.
Frequently asked questions
What is the MikroTrick RouterOS vulnerability?
MikroTrick is the name CERT Polska gave to a set of chained RouterOS vulnerabilities that let an unauthenticated attacker who can reach a device's SSH service take full administrative control. CISA has added three related CVEs (CVE-2026-86060, CVE-2026-67277 and CVE-2026-67279) to its Known Exploited Vulnerabilities catalog.
Is my MikroTik router affected?
It's affected if it's running an unpatched RouterOS version and has SSH, Winbox or another management service reachable from the public internet. MikroTik says most configurations, where management access is restricted to a local network or VPN, are not at risk.
How do I update RouterOS to fix this?
Update to RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable) or later, via WinBox/WebFig under System > Packages, or by running /system package update print from the command line to check your current version first.
How do I know if my router was already compromised?
Check the system log for a critical entry marking the device as 'Flagged,' and check the user list for an unrecognized account, particularly one named 'ops,' which CERT Polska says attackers typically create after a successful compromise.
What is CISA's Known Exploited Vulnerabilities (KEV) catalog?
It's a public list CISA maintains of vulnerabilities it has confirmed are being actively exploited in real-world attacks, as opposed to bugs that are merely theoretically dangerous. KEV listings carry mandatory, risk-scaled remediation deadlines for federal agencies under Binding Operational Directive 26-04.
Does this affect regular home internet routers?
Only if that router runs MikroTik's RouterOS software, which is common among ISPs, enterprises and some advanced home setups but is not what most mainstream consumer routers run. Checking the brand printed on your router or its admin login page will confirm whether it's a MikroTik device.
Sources
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


