
Attackers Exploited MikroTik RouterOS Flaws a Day Before Patches Shipped
Attackers began compromising internet-exposed MikroTik routers on Sept. 2, a day before the Latvian vendor released fixes and three days before national authorities published the technical detail defenders needed to detect the intrusions.
What is the MikroTrick vulnerability chain?
CERT Polska disclosed six RouterOS vulnerabilities Sept. 5 and gave the two-flaw chain seen in the wild a common name, "MikroTrick." CVE-2026-67276, rated 9.2, is an SSH authentication bypass. RouterOS verified the type and modulus of a public key during authentication but omitted the exponent, letting an attacker who knows a username and the RSA modulus forge a matching key and authenticate without ever hol...