MikroTik's MikroTrick Flaw Chain Grants Router Root With No Password At All
Cybersecurity

MikroTik's MikroTrick Flaw Chain Grants Router Root With No Password At All

CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10 after researchers documented MikroTrick, a two-bug chain in RouterOS that gives attackers full administrative control of Internet-exposed MikroTik routers without a password, SSH key, or completed login.

PublishedSeptember 28, 2026
Read time5 min read
Share

A router bug that needs neither a password nor a key

Security researchers this month disclosed MikroTrick, a two-vulnerability chain in MikroTik's RouterOS that lets an attacker take full administrative control of an Internet-exposed router without a password, an SSH key, or even a completed authentication handshake. The first flaw, CVE-2026-67279, is a state-machine bug in RouterOS's SSH implementation that lets an attacker bypass the normal authentication requirement outright. The second, CVE-2026-86060, is an argument-injection bug in the login process that converts that initial access into full administrative privileges by manipulating the arguments the login handler passes internally. Chained together, the two bugs turn 'reachable on the Internet' into 'fully owned' with no credential theft, phishing, or brute force required.

CISA confirmed the severity of this by adding CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, which is a formal acknowledgment, independent of the researchers' own findings, that this bug is being actively used against real targets. CERT Polska issued its own warning on September 5. MikroTik shipped fixed RouterOS versions, 6.49.21, 7.23.4, and 7.24.2, but attack logs show exploitation as early as September 2, a full day before the patches were available, which means every unpatched device sitting on the Internet during that window was exposed to a zero-day, not a known and patchable bug.

Why a cheap router matters to an enterprise CIO

MikroTik is not a brand most enterprise CIOs think about directly. It is inexpensive, widely used by ISPs, managed service providers, and small branch or retail locations that need routing and firewall functionality without an enterprise hardware budget. That profile is precisely the problem. Cheap, widely deployed, rarely centrally managed, and frequently left running with factory or long-outdated firmware because nobody owns the lifecycle for a $150 router the way they own the lifecycle for a core switch. Multiply that by every branch office, kiosk, or remote retail location a PE-backed portfolio company has accumulated through acquisitions, and you likely have MikroTik hardware in your environment whether or not it is on anyone's asset inventory.

For a retail or multi-location commerce business specifically, this matters because branch and store networking gear is exactly the kind of asset that falls through the cracks between headquarters IT and local operations. A compromised router at a single store location is rarely catastrophic on its own, but at scale it becomes a distributed botnet foothold inside your own network perimeter, capable of pivoting toward point-of-sale systems, local Wi-Fi, or anything else on that segment. The unglamorous nature of the hardware is exactly why it deserves attention rather than dismissal.

The pattern behind edge-device botnets

MikroTrick fits a well-established pattern this year of attackers building large botnets out of consumer and small-business networking gear rather than enterprise servers. These devices are numerous, rarely monitored, almost never running endpoint detection, and their owners frequently do not know an update exists, let alone apply it. A single vulnerability chain with no authentication requirement, discovered and weaponized before a patch even ships, is close to the ideal scenario for an attacker building infrastructure for distributed denial of service, proxy networks for other attacks, or simply a durable foothold that is expensive for defenders to fully eradicate at scale.

The real lesson for enterprise security teams is broader than one vendor: the entire category of small networking appliances, from routers to IoT gateways to building management systems, sits outside most organizations' patch management and asset inventory processes. Those processes were built around servers and laptops, with owners, update cycles, and monitoring agents already assigned. Edge networking hardware at branch locations typically has none of that structure, and attackers have clearly noticed the gap well before most defenders have.

What to check this week

Start with an honest inventory question: does your organization, or any managed service provider operating your branch or retail network connectivity, use MikroTik RouterOS anywhere, and if so, on which firmware versions? If you cannot answer that quickly, that gap is itself the finding, independent of this specific CVE. Where MikroTik devices are found, confirm they are on RouterOS 6.49.21, 7.23.4, 7.24.2, or later, and if not, patch immediately given confirmed active exploitation predating the fix.

Beyond the immediate patch, restrict management access on any router-class device, MikroTik or otherwise, so that SSH and administrative interfaces are never reachable from the open Internet, only from a controlled management network or VPN. That single architectural control would have prevented MikroTrick exploitation regardless of the underlying bug, and it is the same control that would have blunted the Citrix NetScaler and Check Point management-server incidents disclosed the same month. The common thread across all three is exposed management interfaces, which is a fixable, repeatable architectural decision rather than a vendor-specific patching problem.

The roadmap takeaway

If your organization has grown by acquisition, has distributed retail or branch locations, or relies on managed service providers for last-mile connectivity, add small networking appliances to your asset inventory and patch management scope explicitly, with a named owner assigned to it this quarter. This is unglamorous security work, and MikroTrick shows it is exploitable work regardless, since the gap between assuming IT already covered this and the reality that nobody actually owns router firmware across four hundred locations is precisely where the next distributed botnet foothold gets planted.

The broader implication is that edge device hygiene deserves the same budget line and executive attention as endpoint and server security. No single router is individually valuable to an attacker, but the aggregate of thousands of unmanaged devices is exactly how the next large-scale botnet gets built, quietly, inside networks whose owners believed they had already covered the basics, and who will find out otherwise only once that botnet is used against them or, worse, against someone else using their infrastructure.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#mikrotik#routeros#mikrotrick#cve-2026-67279#cve-2026-86060#cisa-kev#botnet