Executive Summary
In September 2026, security researchers discovered MikroTrick, a sophisticated attack chain targeting MikroTik RouterOS devices that allowed attackers to gain administrative access without authentication. The vulnerability chain combined CVE-2026-67279 (SSH authentication bypass via rekeying) and CVE-2026-86060 (privilege escalation through username manipulation) to achieve complete router takeover. Evidence indicates active exploitation occurred before public disclosure, with compromised devices found containing persistent backdoors including unauthorized administrative accounts and scheduled scripts designed to maintain persistence. The attack affected RouterOS versions 6.x and 7.x, with internet-facing routers being primary targets.
This incident highlights the critical evolution of network infrastructure attacks, where threat actors are increasingly targeting edge devices that sit between organizations and the internet, providing unprecedented access to monitor traffic, steal credentials, and establish persistent footholds for lateral movement into internal networks.
Why This Matters Now
Network infrastructure devices are becoming prime targets for nation-state actors and ransomware groups seeking persistent access to organizational networks. With the rise of edge computing and remote work, compromised routers provide attackers with ideal positioning for traffic interception, credential harvesting, and establishing covert command-and-control channels.
Attack Path Analysis
Attackers exploited MikroTik RouterOS vulnerabilities CVE-2026-67279 and CVE-2026-86060 to achieve unauthenticated administrative takeover of internet-facing routers. The attack bypassed SSH authentication through rekeying manipulation, escalated to full admin privileges via malicious username injection, established persistence through scheduled tasks and backup accounts, maintained command and control through the compromised router infrastructure, exfiltrated network traffic and credentials passing through the device, and impacted organizational security by exposing internal networks and creating a persistent foothold for future attacks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-67279 in internet-exposed MikroTik RouterOS devices by manipulating SSH rekeying process to bypass authentication and reach post-login functionality without valid credentials
Related CVEs
CVE-2024-67279
CVSS 9.8An authentication bypass vulnerability in MikroTik RouterOS SSH service allows remote attackers to reach post-authentication functionality by triggering a rekey operation before user authentication completes.
Affected Products:
MikroTik RouterOS – 6.x < 6.49.21, 7.x < 7.23.4, 7.24.x < 7.24.2
Exploit Status:
exploited in the wildCVE-2024-86060
CVSS 8.8A command injection vulnerability in MikroTik RouterOS login helper allows authenticated attackers to supply malicious usernames that are interpreted as trusted identity records, leading to privilege escalation.
Affected Products:
MikroTik RouterOS – 6.x < 6.49.21, 7.x < 7.23.4, 7.24.x < 7.24.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts: Local Accounts
Scheduled Task/Job: Cron
Impair Defenses: Disable or Modify Tools
Masquerading: Masquerade Task or Service
Exploitation for Privilege Escalation
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Network Sniffing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration Standards for System Components
Control ID: 2.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Network Infrastructure Security
Control ID: Network/Environment Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
MikroTik router compromises enable attackers to intercept unencrypted traffic, bypass network segmentation controls, and establish persistent command-and-control channels within telecom infrastructure.
Internet
Network infrastructure attacks on RouterOS devices compromise east-west traffic security and egress filtering capabilities, exposing internet service providers to lateral movement risks.
Financial Services
Router takeover chains threaten HIPAA and PCI compliance requirements for encrypted traffic handling while enabling data exfiltration through compromised network boundaries.
Information Technology/IT
Zero trust segmentation failures and multicloud visibility gaps expose IT organizations to privilege escalation attacks through compromised network infrastructure control planes.
Sources
- MikroTrick: Inside the RouterOS Takeover Chainhttps://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chainVerified
- Vulnerabilities in MikroTik RouterOS actively exploitedhttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/Verified
- MikroTik RouterOS CVE Technical Advisoryhttps://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the blast radius of this MikroTik router compromise by limiting lateral movement through segmentation and reducing the scope of network access even after initial device takeover.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native workloads would likely remain isolated from compromised network infrastructure through application-layer segmentation that operates independently of underlying router security controls
Control: Zero Trust Segmentation
Mitigation: Administrative privileges on network devices would likely not translate to elevated access within segmented cloud environments that enforce identity-based access controls independent of network layer credentials
Control: East-West Traffic Security
Mitigation: Lateral movement between cloud workloads would likely be constrained through application-aware segmentation that validates connections independent of network routing infrastructure integrity
Control: Multicloud Visibility & Control
Mitigation: Command and control communications from compromised infrastructure would likely be constrained through centralized policy enforcement that monitors and controls cloud workload connectivity patterns
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration paths would likely be constrained through controlled egress policies that limit cloud workload outbound access regardless of underlying network infrastructure compromise
Overall organizational impact would likely be reduced through workload isolation that limits blast radius even when network infrastructure remains compromised and continues to pose residual risk
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- Internet Connectivity Services
- Network Security Controls
- Remote Access Management
Estimated downtime: 7 days
Estimated loss: N/A
Complete compromise of network traffic, credentials, and internal network access through router takeover. Persistent backdoor accounts and scheduled tasks maintaining unauthorized administrative access. Exposure of configuration data and diagnostic information stored in RouterOS file system.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate network infrastructure devices and limit blast radius of router compromises through identity-based policy enforcement and microsegmentation
- • Deploy multicloud visibility and control systems to detect anomalous traffic patterns and suspicious automation behaviors that could indicate compromised network infrastructure
- • Establish egress security and policy enforcement to prevent unauthorized data exfiltration through compromised network devices and detect traffic to unauthorized destinations
- • Enable threat detection and anomaly response capabilities to identify covert tools, remote access patterns, and baseline deviations that signal infrastructure compromise
- • Implement encrypted traffic controls and east-west traffic security to protect data in transit even when network infrastructure is compromised and prevent lateral movement through network segments



