<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx" -->

---
title: MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers
description: CERT Polska disclosed MikroTrick, an exploit chain combining two critical MikroTik RouterOS vulnerabilities (CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2)...
canonical: https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers | daily.dev
og:description: CERT Polska disclosed MikroTrick, an exploit chain combining two critical MikroTik RouterOS vulnerabilities (CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2)...
og:url: https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx
og:image: https://api.daily.dev/og/posts/80n3a2oRx.png
og:image:alt: MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers

**[Medium](https://daily.dev/sources/medium_js)** · 7 min read · 0 upvotes · 0 comments

## Summary

CERT Polska disclosed MikroTrick, an exploit chain combining two critical MikroTik RouterOS vulnerabilities (CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2) that can bypass SSH authentication and grant full administrator control on routers with SSH exposed to the internet. Roughly 122,500 MikroTik devices were found exposing SSH publicly as of September 5. Fixed versions are 6.49.21, 7.23.4, 7.24.2, and 7.25beta3, with 7.23.5 released afterward to fix an unrelated IPv6 DHCP regression. MikroTik recommends closing SSH to untrusted networks and using a VPN like WireGuard for remote administration instead. CERT Polska also disclosed that it used OpenAI's GPT-5.5-cyber and GPT-5.6-sol models to accelerate the vulnerability research, though human researchers directed and validated the findings.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://meetcyber.net/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-57063a620841>

## Questions this post answers

### What versions of MikroTik RouterOS are vulnerable to the MikroTrick exploit chain?

Vulnerable ranges are RouterOS 6.0.0 through versions below 6.49.21, RouterOS 7.0.0 through versions below 7.23.4, and RouterOS 7.24 through versions below 7.24.2. The flaws are CVE-2026-67276, an SSH public-key authentication bypass, and CVE-2026-86060, a privilege escalation via crafted usernames during SSH login, both rated CVSS 9.2. Fixed releases are 6.49.21, 7.23.4, 7.24.2, and 7.25beta3.

_Teams tracking MikroTik patch status can follow security advisories like this on daily.dev._

### How does the MikroTik SSH public-key authentication bypass vulnerability work?

CVE-2026-67276 exists because RouterOS did not compare the entire RSA public key assigned to an authorized user, only part of it. An attacker who knows the username and the public modulus of that user's key can craft a different key pair and log in without possessing the legitimate private key, effectively bypassing SSH public-key authentication entirely.

_Developers hardening SSH configs can keep up with flaws like this via daily.dev._

### How many MikroTik routers are exposed to the internet and vulnerable to attack right now?

About 122,500 MikroTik devices were found exposing SSH to the internet as of September 5, 2026, according to Shadowserver Foundation data reported by BleepingComputer. This count does not mean all of them are vulnerable or compromised; some may already be patched or may not meet the specific conditions the MikroTrick exploit chain requires.

_Admins auditing exposed infrastructure can track disclosures like this through daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#ssh](https://daily.dev/tags/ssh)

[View this post on daily.dev](https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers","url":"https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx"},"datePublished":"2026-09-10T16:50:19.823Z","dateModified":"2026-09-10T16:52:55.483Z","description":"CERT Polska disclosed MikroTrick, an exploit chain combining two critical MikroTik RouterOS vulnerabilities (CVE-2026-67276 and CVE-2026-86060, both CVSS 9.2)...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f81b23c705ec688cc5ff8b032800c8f1?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f81b23c705ec688cc5ff8b032800c8f1?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Medium","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Medium","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/medium","url":"https://daily.dev/sources/medium_js"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ssh","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Medium","item":"https://daily.dev/sources/medium_js"},{"@type":"ListItem","position":3,"name":"MikroTrick Exploit: Hackers Are Hijacking MikroTik Routers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/mikrotrick-exploit-hackers-are-hijacking-mikrotik-routers-80n3a2orx#faq","mainEntity":[{"@type":"Question","name":"What versions of MikroTik RouterOS are vulnerable to the MikroTrick exploit chain?","acceptedAnswer":{"@type":"Answer","text":"Vulnerable ranges are RouterOS 6.0.0 through versions below 6.49.21, RouterOS 7.0.0 through versions below 7.23.4, and RouterOS 7.24 through versions below 7.24.2. The flaws are CVE-2026-67276, an SSH public-key authentication bypass, and CVE-2026-86060, a privilege escalation via crafted usernames during SSH login, both rated CVSS 9.2. Fixed releases are 6.49.21, 7.23.4, 7.24.2, and 7.25beta3. Teams tracking MikroTik patch status can follow security advisories like this on daily.dev."}},{"@type":"Question","name":"How does the MikroTik SSH public-key authentication bypass vulnerability work?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-67276 exists because RouterOS did not compare the entire RSA public key assigned to an authorized user, only part of it. An attacker who knows the username and the public modulus of that user's key can craft a different key pair and log in without possessing the legitimate private key, effectively bypassing SSH public-key authentication entirely. Developers hardening SSH configs can keep up with flaws like this via daily.dev."}},{"@type":"Question","name":"How many MikroTik routers are exposed to the internet and vulnerable to attack right now?","acceptedAnswer":{"@type":"Answer","text":"About 122,500 MikroTik devices were found exposing SSH to the internet as of September 5, 2026, according to Shadowserver Foundation data reported by BleepingComputer. This count does not mean all of them are vulnerable or compromised; some may already be patched or may not meet the specific conditions the MikroTrick exploit chain requires. Admins auditing exposed infrastructure can track disclosures like this through daily.dev."}}]}
```

