On 5 September CERT Polska said two of the six flaws it found in RouterOS are being combined to take full control of routers with SSH open to the internet. The fixes were announced on 3 September, and the successful attacks go back to at least 2 September.
- The MikroTrick chain gives full control of the router without logging in if SSH is reachable from a public network; CERT Polska does not say which two of the six flaws make it up.
- The successful attacks come from the address 82.192.72.4 and go back to at least 2 September; another trace is a highly privileged user named ops.
- The fixes are in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21; the absence of the Flagged marker does not prove the device is clean.
A user named ops with high privileges. If you don't remember creating it on your MikroTik, don't go looking for a forgotten setting. According to CERT Polska a user like that is a trace that successful attacks on these routers leave behind.
The Polish incident response team published on Saturday, 5 September, that it is seeing attacks on RouterOS routers reachable from the internet. The attackers combine two vulnerabilities and take full control of the device without going through a login. There is one condition: SSH has to be open to the public network.
Which two
Here we have to be precise, because the sources leave a gap. CERT Polska writes that the chain is made of two flaws, but does not say which. In the report it describes three in detail: CVE-2026-67276, which lets you log in over SSH with a forged key, CVE-2026-86060, where a specially chosen username gives full administrator rights, and CVE-2026-67277 in the bandwidth-test service.
MikroTik, for its part, ties the name MikroTrick to exactly those three numbers. Except the third flaw has nothing to do with SSH. As of today neither the Polish team nor the vendor has officially named the two numbers the attacks use. We won't guess them either.
The date in the report weighs more than the numbers. The attacks go back to at least 2 September, and MikroTik's bulletin is from the 3rd. The attacker was inside, before the patch announcement was out.
CERT Polska also writes why it is in a hurry. The patched packages are public, and by comparing them with the old ones the community has already reconstructed some of the fixed bugs. And one more sign that this is no minor bug: for the first time in its history, MikroTik sent a notification to the phones of users who have its app installed.
The flag
The patched versions scan the configuration at startup, disable known traces of tampering, write a critical entry to the log and mark the device as Flagged. The mechanism, CERT Polska warns, only catches selected traces.
The order of work comes from the report itself. You update to one of the fixed versions. In the log you look for the critical entry about the marker and for lines where a user -2 shows up over SSH. Then you check for unknown users, scripts, scheduler tasks, proxy servers and tunnels.
Can't update today? You close SSH, the web interface and the bandwidth-test server to everything outside the trusted management network. And from the unpatched router you don't start TLS connections or use its built-in SSH client. That narrows the way in, it doesn't close it.
Find a trace, and the router is no longer yours. You isolate it, save the log and the configuration, reset it to factory settings and change every password and key. You don't blindly load the old backup back, because it comes from a device that was already taken over.