Ethical Hacking News
Security researchers have discovered a critical vulnerability in MikroTik RouterOS SSH protocol that could compromise the security of its devices. The vulnerability, known as MikroTrick, allows attackers to gain full control of MikroTik routers without authentication. Users are advised to patch their devices immediately and be vigilant for suspicious activity.
MikroTik has revealed a critical vulnerability in its RouterOS SSH protocol, known as MikroTrick, which allows attackers to gain full control of MikroTik routers without authentication. The vulnerability is a combination of two existing vulnerabilities: CVE-2026-67276 and CVE-2026-86060, which allows an attacker to bypass SSH authentication and escalate SSH session privileges. The vulnerability was discovered by CERT Polska and is being actively exploited, prompting users to treat their MikroTik routers as compromised until proven otherwise. Patches have been released for versions 7.25beta3, 7.24.2, 7.23.4, 7.23.5, and 6.49.21 to address the vulnerability. Users can detect attacks by looking for specific log entries, such as failed login attempts and successful attacks with specific usernames. The vulnerability highlights the importance of keeping software up-to-date, securing devices against exploitation, and monitoring device logs for suspicious activity.
The latest security alert has left the cybersecurity community buzzing with concern. MikroTik, a popular router brand, has revealed a critical vulnerability in its RouterOS SSH protocol that could compromise the security of its devices. The vulnerability, known as MikroTrick, allows attackers to gain full control of MikroTik routers without authentication, posing a significant threat to network security.
The MikroTrick vulnerability is a result of a combination of two vulnerabilities: CVE-2026-67276, which allows an attacker to bypass SSH authentication, and CVE-2026-86060, which enables SSH session privilege escalation. This combination allows an attacker to take control of the device without authentication, making it a critical vulnerability.
The vulnerability was discovered by CERT Polska, a Polish cybersecurity team, who identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. The CERT team has warned that the vulnerability is being actively exploited, and users should treat their MikroTik routers as compromised until proven otherwise.
The MikroTrick vulnerability is particularly concerning because it can be exploited by anyone with knowledge of the vulnerability. The attackers are using a busybox binary, launched.sh, and serve.py files to exploit the vulnerability. These files are hosted on a Leaseweb IP, and the attackers are using them to spread the malware.
MikroTik has released patches for the vulnerability in versions 7.25beta3, 7.24.2, 7.23.4, 7.23.5, and 6.49.21. However, the vulnerability is already being actively exploited, and users should patch their devices immediately.
To detect attacks, users can look for specific log entries, such as failed login attempts with the username "-2", or successful attacks with the username "ssh:-2@". They can also check for the creation of an "ops" account, which is an additional confirmed indicator of compromise.
The MikroTik RouterOS SSH vulnerability highlights the importance of keeping software up-to-date and securing devices against exploitation. It also emphasizes the need for cybersecurity awareness and the importance of monitoring device logs for suspicious activity.
In conclusion, the MikroTik RouterOS SSH vulnerability is a critical security issue that requires immediate attention. Users should patch their devices immediately and be vigilant for suspicious activity. The cybersecurity community must stay alert and monitor for new vulnerabilities to prevent future attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-the-MikroTik-Router-Vulnerability-A-Threat-to-Network-Security-ehn.shtml
https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html
https://nvd.nist.gov/vuln/detail/CVE-2026-67276
https://www.cvedetails.com/cve/CVE-2026-67276/
https://nvd.nist.gov/vuln/detail/CVE-2026-86060
https://www.cvedetails.com/cve/CVE-2026-86060/
Published: Sun Sep 6 10:13:55 2026 by llama3.2 3B Q4_K_M