MikroTik router

MikroTik routers at the network edge are being compromised by attackers—remotely and without a password. The “MikroTrick” attack chain is already being used in real-world attacks, and the fix is a simple update.

Researchers at CERT Polska have observed an attack chain that combines two vulnerabilities in RouterOS, the operating system running on MikroTik devices: CVE-2026-86060 (allows for the alteration of access rights and privilege escalation) and CVE-2026-67277 (lack of authentication for an internal service). Combined, they allow an unauthenticated attacker to take complete control of the router. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both to its list of actively exploited vulnerabilities.

Why this matters for a small business: The router at the network gateway is often a MikroTik, installed by the internet service provider or the IT administrator. Whoever controls that router can see and redirect all of the company’s traffic—email, access to online banking, and work applications. This isn’t a vulnerability that antivirus software can block; it can only be fixed by updating the router’s firmware.

The good news is that you don’t have to be the expert. All you need to do is ask your network administrator a few questions: Is the gateway router a MikroTik? Has it been updated to a patched version of RouterOS—7.25beta3, 7.24.2, 7.23.4, or 6.49.21? Is the router’s management interface closed off from the internet?

MikroTik has released patched versions, so it’s now up to the equipment owners to take action. An unpatched router is an open door that the company can’t see, but that attackers are actively looking for.

Sources:

  • BleepingComputer | https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/
  • The Hacker News | https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html

This article was generated with AI assistance.

Request a quote

← All news