Daily Edition
Cyber Security · Thursday, September 10, 2026 · 2 sources

Latvian router maker MikroTik patches six flaws already exploited in MikroTrick attacks

Polish security researchers at CERT Polska found six vulnerabilities in RouterOS, the operating system of Latvian networking vendor MikroTik. Two of them, chained as MikroTrick, let attackers take over internet-exposed SSH devices without authentication; attacks have been recorded since at least 2 September. MikroTik has issued patches, but over 122,500 devices remain exposed. Administrators should update, rotate credentials, and check for unauthorised changes.

Bottom line — With 122,500+ SSH-exposed MikroTik devices, any unpatched router is a takeover target; update RouterOS now.

Go deeper (10)

  • The two most severe flaws — CVE-2026-67276 and CVE-2026-86060, both rated CVSS 9.2 — chain together to bypass SSH authentication and escalate to full administrative access without authentication, according to CERT Polska.
  • Observed attacks since at least 2 September created a highly privileged account named 'ops'; failed logins involving a user '-2' preceded account additions through SSH, the Polish team said.
  • MikroTik has released fixes in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21, and recommends not exposing SSH on the internet interface; the company said RouterOS will set a 'Flagged' status on devices with signs of unauthorised changes.
  • Shadowserver Foundation scans found 122,500+ MikroTik devices with SSH reachable from the internet, mostly in Brazil, the US and Indonesia.
  • CERT Polska warned that the 'Flagged' marker indicates possible earlier compromise, not proof of exploitation; its absence likewise does not mean a device is safe.
  • A third bug, CVE-2026-67277 (CVSS 8.8) in the bandwidth-test service, could leak kernel memory or force a remote restart, the researchers said.
  • The flaws affect the SSH server and client, bandwidth-test service, X.509 certificate handling and WebFig interface, per CERT Polska.
  • CERT Polska linked the exploit activity to IP address 82.192.72.4, with 103.102.31.18 used in exploitation attempts.
  • CERT Polska discovered the vulnerabilities with OpenAI GPT-5.5-cyber and GPT-5.6-sol models in an agent-based lab, but stressed that researchers manually verified each finding on real RouterOS systems.
  • MikroTik sent a push notification about the update to phones with its app installed — a first for the company, the alert noted.

Read the reporting

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 10, 7:27 AM UTC by wreetco wreetco

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 10, 7:27 AM UTC by wreetco wreetco