KOM CLOUDSERVICE
All Insights

MikroTik Routers Are Being Taken Over Without a Password

Attackers are chaining two RouterOS flaws to seize full control of internet-exposed MikroTik routers. Here's what to check and fix this week.

CERT Polska is warning that attackers are actively exploiting a pair of MikroTik RouterOS flaws to take over routers that have their remote management exposed to the internet. The chain has a name: MikroTrick. No password required. Malwarebytes has the writeup, and the short version is that if you own a MikroTik router with SSH reachable from the internet, you need to deal with it this week.

The warning came from Poland’s national response team, but MikroTik sells worldwide, including plenty into US small businesses. These routers show up in offices because they are cheap, powerful, and popular with the kind of IT person who likes knobs to turn. If someone set up your network on a budget and you have a small blue-and-white box in the closet, go look at the label.

What the flaws actually do

MikroTik disclosed six vulnerabilities. Two of them combine into the attack chain being exploited.

The first, CVE-2026-67276, is an authentication bypass in how RouterOS handles RSA public keys during SSH login. SSH is the encrypted remote-administration protocol admins use to log into network gear. Bypass means the attacker gets in without valid credentials at all.

The second, CVE-2026-86060, is a privilege escalation triggered by a specially crafted username during SSH login. Once inside, the attacker promotes themselves to administrator.

Get in without a password, then become the admin. That is the whole story, and it is why a strong password on the router does not help you here. There is no password check to fail.

CERT Polska went public specifically because the patched RouterOS packages are already out, and the security community has been able to reconstruct some of the fixed flaws by comparing patched code to unpatched code. That is the usual pattern: once a patch ships, the clock starts, and the people writing exploits move faster than the people applying updates.

Why a router is worse than a laptop

When a workstation gets popped, you have one infected machine. When the router gets popped, the attacker owns the door everyone walks through.

From a compromised edge router, an intruder can change your DNS settings so that “yourbank.com” quietly resolves wherever they want. They can redirect or capture traffic passing through. They can rewrite firewall rules to open up anything they like. They can build a remote-access tunnel so they keep a permanent way back in. And they can use the router as a launch point to attack the printers, servers, cameras, and PCs behind it.

None of that trips your antivirus. It happens below the machines you monitor. That is exactly why edge devices are having a rough year. A week ago SonicWall disclosed two SMA1000 remote-access flaws, including one rated a maximum-severity 10.0, and Sophos confirmed both are being exploited in the wild. We wrote about ransomware crews hitting SonicWall remote access in an earlier post. Different vendor, same lesson: the box guarding your network is now the target.

What to do this week

1. Update RouterOS. Use the router’s own update mechanism (Check for updates) or pull the supported package directly from MikroTik. This is the fix. Everything else is damage control.

2. Take management off the internet. SSH should not be reachable from untrusted networks, period. If you genuinely need remote administration, restrict it to a short list of known IP addresses. Remote management should be an exception you deliberately allow, not a default you never noticed was on.

3. Check the flag. MikroTik added a startup check that scans the configuration for signs of unauthorized changes. If it finds any, RouterOS disables the suspicious entries and sets the device’s Flagged status to Yes. Run /system/device-mode/print to see it. While the device is flagged, RouterOS restricts several abusable functions.

4. Do not just clear the flag and move on. MikroTik is explicit about this: the full configuration still needs to be audited before you clear it. Look at DNS servers, firewall rules, VPN and tunnel definitions, scheduled scripts, and the list of user accounts. If an attacker was in there, the goal was persistence, and persistence lives in config.

5. Write down what you own. Router make, model, firmware version, who has admin access, and whether management is exposed. Most small businesses cannot answer the MikroTik question today because nobody has that list. Building it once turns every future advisory into a five-minute check instead of a bad afternoon.

Patching network gear and keeping an inventory of what is exposed is unglamorous work, which is why it is usually the thing that has not been done. It is part of what we handle as ongoing managed IT for clients, alongside the endpoint and network monitoring that catches the follow-on activity when an edge device does get hit.

If you have a MikroTik in the closet and no idea what firmware it is running, that is worth twenty minutes of someone’s attention. Book a free 15-minute consult and we will tell you straight whether you are exposed.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever