we_are_coded.by CODE · The world, decoded
БГ
CERT Polska

Poland's CERT confirmed attacks on MikroTik routers over SSH that began at least a day before the patch bulletin

CERT Polska · event date: 7 September 2026Security

On 5 September CERT Polska said two of the six flaws it found in RouterOS are being combined to take full control of routers with SSH open to the internet. The fixes were announced on 3 September, and the successful attacks go back to at least 2 September.

In short
  • The MikroTrick chain gives full control of the router without logging in if SSH is reachable from a public network; CERT Polska does not say which two of the six flaws make it up.
  • The successful attacks come from the address 82.192.72.4 and go back to at least 2 September; another trace is a highly privileged user named ops.
  • The fixes are in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21; the absence of the Flagged marker does not prove the device is clean.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

A user named ops with high privileges. If you don't remember creating it on your MikroTik, don't go looking for a forgotten setting. According to CERT Polska a user like that is a trace that successful attacks on these routers leave behind.

The Polish incident response team published on Saturday, 5 September, that it is seeing attacks on RouterOS routers reachable from the internet. The attackers combine two vulnerabilities and take full control of the device without going through a login. There is one condition: SSH has to be open to the public network.

The facts: on 5 September 2026 CERT Polska said it had found and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS: CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060. They affect the SSH server and client, the bandwidth-test service, X.509 certificate handling and the WebFig web interface. According to the team, a combination of two of them, which it calls MikroTrick, allows full control of the device without authentication if it accepts remote access over SSH, and is already being used against devices with SSH reachable from public networks. The successful attacks, including the creation of an ops account, come from the address 82.192.72.4 and have been happening since at least 2 September; the address 103.102.31.18 was used for attempts. The fixes are in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21 and, according to CERT Polska, stop the observed attacks. MikroTik announced the fixes in a bulletin dated 3 September, saying most configurations are not at risk but upgrading is highly recommended; in its updated version it advises that SSH not be open to untrusted networks and ties the name MikroTrick to CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. The vulnerabilities were found with OpenAI's GPT-5.5-cyber and GPT-5.6-sol models, through the GTAC program.

Which two

Here we have to be precise, because the sources leave a gap. CERT Polska writes that the chain is made of two flaws, but does not say which. In the report it describes three in detail: CVE-2026-67276, which lets you log in over SSH with a forged key, CVE-2026-86060, where a specially chosen username gives full administrator rights, and CVE-2026-67277 in the bandwidth-test service.

MikroTik, for its part, ties the name MikroTrick to exactly those three numbers. Except the third flaw has nothing to do with SSH. As of today neither the Polish team nor the vendor has officially named the two numbers the attacks use. We won't guess them either.

The date in the report weighs more than the numbers. The attacks go back to at least 2 September, and MikroTik's bulletin is from the 3rd. The attacker was inside, before the patch announcement was out.

CERT Polska also writes why it is in a hurry. The patched packages are public, and by comparing them with the old ones the community has already reconstructed some of the fixed bugs. And one more sign that this is no minor bug: for the first time in its history, MikroTik sent a notification to the phones of users who have its app installed.

The flag

The patched versions scan the configuration at startup, disable known traces of tampering, write a critical entry to the log and mark the device as Flagged. The mechanism, CERT Polska warns, only catches selected traces.

The flag says something happened. Its absence says nothing.

The order of work comes from the report itself. You update to one of the fixed versions. In the log you look for the critical entry about the marker and for lines where a user -2 shows up over SSH. Then you check for unknown users, scripts, scheduler tasks, proxy servers and tunnels.

Can't update today? You close SSH, the web interface and the bandwidth-test server to everything outside the trusted management network. And from the unpatched router you don't start TLS connections or use its built-in SSH client. That narrows the way in, it doesn't close it.

Find a trace, and the router is no longer yours. You isolate it, save the log and the configuration, reset it to factory settings and change every password and key. You don't blindly load the old backup back, because it comes from a device that was already taken over.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CERT Polska - Critical vulnerabilities in MikroTik RouterOS are being actively exploited, 05.09.2026→CERT Polska - Vulnerabilities in Mikrotik RouterOS software (CVE list), 05.09.2026→MikroTik - September 2026 vulnerability, 03.09.2026
Original: https://wearecoded.com/en/articles/mikrotrick-cert-polska-ataki-prez-ssh.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news