High

MikroTik, RouterOS, MikroTrick, SSH, Router Security, CERT Polska, Edge Security

MikroTik MikroTrick: Unauth SSH Router Hijack in Wild

MikroTik MikroTrick is a two-flaw chain letting attackers take full admin control of internet-exposed MikroTik routers over SSH without authentication. Update RouterOS now.

MikroTik MikroTrick is a two-flaw chain that attackers are using to take full administrative control of internet-exposed MikroTik routers over SSH without any authentication, according to a CERT Polska warning published September 5, 2026. Successful attacks date to at least September 2. CERT Polska named the reported two-vulnerability combination MikroTrick, and MikroTik has published fixed RouterOS releases that CERT says prevent the observed attacks. There is no public victim count or attacker attribution as of the September 6 review of the warning.

CERT recommends installing the fixed RouterOS release immediately and then checking for unauthorized configuration changes, because a router that has already been hijacked will not clean itself when patched. Neither CERT's warning nor the vulnerability disclosure explicitly names which two flaws form the observed chain or how they combine to grant administrative access, so defenders should treat any exposed, unpatched device as potentially at risk rather than wait for full technical detail.

Until the update can be applied, CERT advises turning off exposed services or restricting them to trusted management networks, especially SSH, WWW and WWW-SSL, and the bandwidth-test service. It also warns against initiating TLS connections or using RouterOS's built-in SSH client from an unpatched device, since those actions can be abused as part of the broader vulnerability set. MikroTik notes that home devices with default firewall rules intact already block public access to management ports, so the highest risk is to devices where those defaults were changed to expose management.

How do you tell if a MikroTik router is already compromised?

Check the device's Flagged status and logs. RouterOS flags a device when startup checks detect suspicious configuration, disabling those entries and restricting some functions; after updating, run /system/device-mode/print and review the logs. Even with no warning, inspect the configuration for unknown users, unrecognized scripts, and other changes you did not make. CERT specifically calls out unexpected highly privileged operator accounts and account-creation log entries containing ssh:-2@ as indicators to investigate.

What should MikroTik admins do first?

Update to the fixed RouterOS version from the official download page, then hunt for compromise before clearing anything. If logs, configuration, or the Flagged status suggest a breach, preserve the evidence first and complete analysis before removing the flag, because clearing it destroys forensic state. The 7.23.5 regression fix also resolves an IPv6 DHCP problem introduced in 7.23.4 while keeping the security fix, so it is the safe target for affected trains.

Detail

Value

Name

MikroTrick (two-flaw chain)

Access

Unauthenticated full admin over exposed SSH

Source

CERT Polska advisory, September 5, 2026

First seen

At least September 2, 2026

Fix

Updated RouterOS releases (7.23.5 for affected train)

Key IoC

Ops accounts and ssh:-2@ account-creation log entries

Our read

Edge devices like routers are the perfect target because they sit on the internet by definition, often run for years without patching, and grant deep network access once owned. MikroTrick follows the familiar pattern: management services reachable from the internet, an unauthenticated path to admin, and quiet in-the-wild use before most operators even hear about it. The durable lesson is that router management planes should never be exposed to the public internet in the first place. The defensible posture is to verify from the outside that SSH and web management are unreachable, patch on a real schedule, and treat any exposed device as suspect until its configuration has been audited.

Reporting by The Hacker News; advisory, indicators, and mitigations per CERT Polska; fixed releases per MikroTik. Sources linked above.

Related: What is privilege escalation? and How to prioritize vulnerabilities.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.