Executive Summary
In September 2026, attackers exploited the MikroTrick vulnerability chain (CVE-2026-67279 and CVE-2026-86060) to gain full administrative control of internet-exposed MikroTik routers without passwords or SSH keys. The attack combined an SSH state-machine flaw that bypassed authentication with an argument-injection vulnerability in RouterOS login process. Evidence shows active exploitation began September 2, 2026, one day before patches were released, with attackers creating privileged accounts and exfiltrating configuration data from compromised devices.
This incident highlights the growing threat to network infrastructure devices as nation-state actors and cybercriminals increasingly target routers and edge devices for persistent access and lateral movement capabilities.
Why This Matters Now
Network infrastructure devices like routers have become primary targets for establishing persistent footholds in enterprise networks, with recent campaigns by groups like Salt Typhoon demonstrating how compromised edge devices enable long-term espionage and data theft operations.
Attack Path Analysis
Attackers exploited the MikroTrick vulnerability chain (CVE-2026-67279 and CVE-2026-86060) against Internet-exposed MikroTik routers to gain unauthenticated administrative access, created privileged user accounts, and exfiltrated router configurations to attacker infrastructure for potential network reconnaissance and further compromise.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers targeted Internet-exposed MikroTik RouterOS SSH services, exploiting CVE-2026-67279 to bypass authentication by initiating SSH key renegotiation during the authentication phase, allowing progression to command execution without valid credentials.
Related CVEs
CVE-2024-67279
CVSS 9.8SSH state machine vulnerability in MikroTik RouterOS allows unauthenticated clients to bypass authentication during key renegotiation and reach command execution phase without proper user verification.
Affected Products:
MikroTik RouterOS – < 6.49.21, < 7.23.4, < 7.24.2
Exploit Status:
exploited in the wildCVE-2024-86060
CVSS 9.8Argument injection vulnerability in MikroTik RouterOS login process allows attackers to inject malicious command-line arguments and achieve full administrative privileges by manipulating username input.
Affected Products:
MikroTik RouterOS – < 6.49.21, < 7.23.4, < 7.24.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Exploitation for Privilege Escalation
Create Account: Local Account
Process Injection
Archive Collected Data
Exfiltration Over C2 Channel
Remote System Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.02(g)
PCI DSS 4.0 – Configuration Standards
Control ID: 2.2.1
CISA Zero Trust Maturity Model 2.0 – Device Identity
Control ID: ID.AM-1
DORA – ICT Risk Management
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
NIST Cybersecurity Framework – Vulnerability Management Plan
Control ID: PR.IP-12
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
MikroTik routers are critical network infrastructure for ISPs and telecom providers, making SSH vulnerabilities expose entire network segments to administrative takeover and traffic interception.
Internet
Internet service providers relying on MikroTik routing equipment face complete network compromise through SSH exploitation, enabling attackers to control traffic flows and steal configuration data.
Information Technology/IT
IT infrastructure using MikroTik devices for network segmentation and connectivity becomes vulnerable to lateral movement attacks, compromising zero trust architectures and encrypted traffic controls.
Government Administration
Government networks utilizing MikroTik routers face critical national security risks from unauthenticated administrative access, potentially exposing classified communications and sensitive governmental operations.
Sources
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Keyhttps://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.htmlVerified
- MikroTrick Technical Analysis - CERT Polskahttps://cert.pl/en/posts/2024/09/mikrotrick-technical-analysis/Verified
- MikroTik RouterOS September 2024 Security Vulnerability Advisoryhttps://mikrotik.com/supportsec/september-2024-vulnerability/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- MikroTrick Chain Let Attackers Take Over MikroTik Routers - The Hacker Newshttps://thehackernews.com/2024/09/mikrotrick-chain-let-attackers-take.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly reduced the blast radius of this MikroTik router compromise by constraining lateral movement and limiting the attacker's ability to pivot into segmented network zones.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have limited the attacker's initial foothold to isolated perimeter zones, reducing their ability to immediately access critical internal infrastructure segments.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely have restricted the scope of administrative privileges available to the compromised router, limiting its ability to influence broader network routing decisions.
Control: East-West Traffic Security
Mitigation: Microsegmentation enforcement would likely have blocked unauthorized east-west traffic flows from the compromised router, significantly limiting the attacker's ability to reach internal network segments and critical assets.
Control: Multicloud Visibility & Control
Mitigation: Network traffic inspection and anomaly detection would likely have identified suspicious command and control communications, limiting the attacker's ability to maintain persistent administrative access across network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have blocked or flagged unauthorized outbound data transfers from network infrastructure components, reducing the attacker's ability to exfiltrate sensitive configuration and topology information.
The overall network impact would likely have been significantly reduced through segmentation boundaries, limiting the attacker's surveillance scope to isolated network zones rather than enterprise-wide infrastructure visibility.
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- Internet Gateway Services
- Remote Access Management
- Network Security Operations
Estimated downtime: 3 days
Estimated loss: N/A
Complete router configuration data, network topology information, authentication credentials, VPN configurations, and administrative access credentials were potentially exfiltrated to attacker infrastructure at IP addresses 82.192.72.4 and 103.102.31.18.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate network infrastructure devices and limit lateral movement from compromised routers
- • Deploy egress security controls to detect and block unauthorized diagnostic file transfers and configuration data exfiltration
- • Enable multicloud visibility and anomaly detection to identify suspicious SSH authentication patterns and failed login attempts for unusual usernames like '-2'
- • Establish encrypted traffic monitoring to detect unencrypted management protocols and implement secure hybrid connectivity for infrastructure management
- • Apply inline intrusion prevention with signature-based detection to identify and block known exploit patterns targeting network device vulnerabilities



