MikroTik RouterOS Authentication Bypass and RCE
The 'MikroTrick' campaign exploits vulnerabilities in the RouterOS SSH service to achieve unauthenticated remote code execution and administrative account persistence.
CVE search metadata
CVE search record: CVE-2026-86060. Severity: critical. CVSS: 9.8. EPSS: 1.85%. KEV: no. Product: RouterOS (< 6.49.21), RouterOS (7.0 <= 7.23.3), RouterOS (7.24.0 <= 7.24.1), RouterOS. Brief: MikroTik RouterOS Authentication Bypass and RCE. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotrick-rce/
CVE search record: CVE-2026-67279. Severity: medium. CVSS: 6.5. EPSS: 1.03%. KEV: no. Product: RouterOS (< 6.49.21), RouterOS (7.0 <= 7.23.3), RouterOS (7.24.0 <= 7.24.1), RouterOS. Brief: MikroTik RouterOS Authentication Bypass and RCE. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mikrotrick-rce/
What's new
- 1. new product Sep 30, 16:22 via bsi
The 'MikroTrick' campaign exploits a series of vulnerabilities in the MikroTik RouterOS SSH service to achieve unauthenticated remote code execution. Active since September 2026, this threat leverages a sequence of bugs in the SSH session handling mechanism to bypass authentication gates. By initiating an unauthenticated session and manipulating the state machine via a forced rekeying process, an attacker can escalate privileges to full administrative control (the 'full policy set'). The exploit essentially tricks the system into treating a custom, attacker-controlled policy mask as legitimate during the login helper process. Once control is gained, the attacker typically plants a persistent administrative account, 'hacker', to ensure ongoing access. This vulnerability affects multiple versions across both the 6.x and 7.x branches of RouterOS. Defenders should prioritize patching or restricting SSH access to trusted management subnets.
Attack Chain
- Attacker sends a user authentication request with the username '-2', which is rejected by the server but persists as a 'pending' state.
- Attacker triggers a SSH rekeying request before completing any authentication handshake.
- The rekeying process exploits CVE-2026-67279, causing the server to lose its mandatory authentication gate check.
- Attacker opens an unauthenticated session channel using the 'pending' '-2' username state.
- Attacker spawns the interactive shell, invoking '/nova/bin/login' which consumes the identity and policy-mask values provided by the attacker.
- Attacker provides a malicious identity ('0') and policy mask ('4294967295'), which the login helper treats as elevated permissions (CVE-2026-86060).
- The SSH session is promoted to full administrative rights, granting the attacker control over the RouterOS console.
- Attacker executes system commands to add a new user 'hacker' with 'full' group privileges for persistent access.
Impact
Successful exploitation results in full administrative control over the affected MikroTik router. Attackers can leverage this to exfiltrate configurations, intercept traffic, or pivot into the internal network. The campaign has been observed in the wild since September 2, 2026, posing a direct threat to any internet-facing RouterOS device.
Recommendation
- Upgrade RouterOS to the patched versions: 6.49.21, 7.23.4, or 7.24.2 immediately.
- Restrict access to the SSH service (port 22) to specific, trusted management IP addresses using firewall filters.
- Audit existing user accounts for any unauthorized entries, specifically looking for the 'hacker' user or accounts created with 'full' group privileges.
- Deploy network-based detection to monitor for suspicious SSH authentication failures or anomalous rekeying behavior targeting network infrastructure.
Immediate actions
Upgrade all MikroTik RouterOS instances to 6.49.21, 7.23.4, or 7.24.2.
Mitigations
Block SSH access from untrusted networks to RouterOS devices.
CVE-2026-86060