Security & Risk5 minNewsroom

MikroTrick Chain Exposes MikroTik Routers to the Internet Without Authentication, Warns CERT Polska

Sala de operações de provedor de internet à noite com rack de roteadores MikroTik e um técnico observando o console de terminal.

CERT Polska coordinated the disclosure of six vulnerabilities in RouterOS; the combination of two of them allows remote root control via SSH without credentials and is already being exploited.

CERT Polska disclosed on September 6 six vulnerabilities in MikroTik RouterOS that the agency received from external researchers and coordinated with the manufacturer. Two of these, when chained together, allow a remote attacker to execute code as root on any router that exposes the SSH service to the internet, without presenting credentials. The Polish agency dubbed the chain MikroTrick and claims to have registered exploitation attempts even before the public disclosure.


The Two Vulnerabilities That Enable the Chain


The first link, cataloged as CVE-2026-67276, is a flaw in the comparison of the RSA public key used to authenticate SSH sessions. RouterOS accepts as valid a signature whose modulus matches that of an authorized key, without checking the remaining cryptographic material. An attacker who knows the public modulus of an authorized user can forge signatures and open an SSH shell on behalf of that identity, even without possessing the private key.


The second link, CVE-2026-86060, affects the policy mask that RouterOS applies based on the username provided at login. Usernames starting with a prohibited character cause the interpreter to skip the check and adopt the most permissive profile. Combined with the flaw in RSA validation, this second piece converts the access obtained without real authentication into an administrative session. CERT Polska's warning describes four other flaws disclosed in the same package, including file reading as root without authentication in the /jsproxy path of the WebFig interface, useful for attackers who want to inventory the device before the next step.


MikroTik confirms in its security advisory that corrected releases have been published across all channels, including stable and long-term, and recommends immediate updates for operators exposing SSH or WebFig to the internet. The manufacturer also advises restricting management plans via firewall list and rotating authorized keys after the update. The protection window is short: in previous zero-day cycles on edge routers, the interval between public disclosure and mass scanning was measured in hours, not days.


Why MikroTik is the Target


RouterOS is the foundation for a large part of the last mile in regions where the cost per gigabit outweighs brand preference. Regional providers in Latin America, Southeast Asia, and Eastern Europe operate fleets of thousands of units managed en masse via SSH. In Brazil, MikroTik equips a significant portion of the operations of independent providers serving medium-sized cities and rural areas, the segment that Anatel classifies as small providers and that accounts for half of the fixed broadband base in recent cycles, close to 24 million residential accesses when regional PPPs are aggregated.


The European standard is similar, with concentrations in Poland, the Czech Republic, and Germany, countries where MikroTik emerged as a reference for wireless ISPs. An average provider with a thousand routers in the field, without an updated inventory, needs to map within hours which units expose SSH to the internet, which run vulnerable versions, and which accept remote updates without going through the end customer. CERT Polska states that ongoing attacks are still from operators testing the vector in bulk, but the public script reveals the recipe for any actor wanting to build a botnet or pivot into the subscriber's network, a scenario reminiscent of VPNFilter in 2018 and Cyclops Blink in 2022, both originating from unpatched access routers.


What Changes for the CISO


Two interpretations arise for the security team. First, the vector does not require social engineering or pre-loaded malware: anyone with the RSA modulus of an authorized key, or who knows how to circumvent the username check, can enter as an administrator. Second, the compromised surface is not a data center; it is the access network. EDR tools do not monitor this layer, and many operations relying on MikroTik in the field outsource management to regional integrators who operate on monthly schedules, not emergency ones.


The immediate manual is the same as always in edge device failure: close SSH to the public, restrict origin via firewall list, rotate authorized keys, apply the corrected versions announced by the manufacturer. Outside the checklist, the coordination of CERT Polska signals something new. National European agencies are beginning to take the technical lead in a product class that rarely appears in zero-day bulletins. If this posture spreads, other CERTs will adopt the same coordination discipline for access routers, an area historically left to manufacturer bulletins and fragmented coverage by the specialized press, and the CISO will start receiving official alerts about platforms currently invisible in their risk inventory. However, the gain in signal comes at a cost: when the alert becomes public, the race begins.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk