CERT Polska has detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that lets an unauthenticated attacker gain full administrative control of Internet-exposed routers. The first flaw, CVE-2026-67279, breaks the SSH state machine: if a client starts key renegotiation during authentication, vulnerable RouterOS moves to the command phase without confirming identity. The second, CVE-2026-86060, is an argument-injection bug in the login process. Sending -2 as the username makes /nova/bin/login read identity and privilege level from file descriptor 2, where the attacker has already placed an admin username and privilege value.
The chain does not require a password, SSH key, or completed authentication. CERT Polska says logs matching the attack pattern appeared on MikroTik's forum as early as September 2, one day before patches were released in RouterOS 6.49.21, 7.23.4, and 7.24.2. In observed incidents, attackers created a full-privilege account named ops, and in some cases copied configuration data to an attacker-controlled IP address. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, independently confirming active exploitation.
Patching stops the attack but does not undo changes made before the update. CERT Polska and MikroTik advise administrators to check /system/device-mode/print for Flagged status, and to look for unknown users, scripts, scheduler entries, tunnels, proxies, unexpected .rif files, or unexplained fetch activity. If indicators are found, isolate the device, preserve logs and configuration, factory reset, and rebuild from a trusted configuration; do not restore backups from a compromised device. CERT Polska notes that the Flagged mechanism only detects selected traces, so a clean result does not prove the device is safe.