The CERT Polska team was enough for about an hour after the release of the urgent MikroTik update to detect a new critical hole and restore the path to complete administrative access without a password. A significant part of the analysis was performed by AI agents on the GPT-5.5-cyber and GPT-5.6-sol models, but experts separately emphasize that each result was then tested in an isolated laboratory.
The story began on September 3, when MikroTik almost simultaneously released RouterOS 7.24.2, 7.23.4, 6.49.21 and 7.25beta3, calling the update important, but not revealing details. The urgency quickly attracted the attention of specialists, and the magazines of hacked devices that appeared in the network showed a strange picture: RouterOS first recorded the unsuccessful user's entrance -2, and then an account appeared in the same session ops with full rights. First details real attacks appeared almost immediately after the release of the corrections.
A comparison of the old and new builds showed that MikroTik added a username check before transmitting data to the internal program /nova/bin/login. The team of CERT Polska compared the change with the attacks logs and in an hour revealed CVE-2026-86060. The vulnerability allowed the specially formed username to influence the arguments of the service program and replace the privilege mask that RouterOS considered trusted.
One CVE to enter without a password was not enough. The second part of the chain was CVE-2026-67279 in the SSH server RouterOS. When the keys were re-agreed before the authentication was completed, the server could mistakenly proceed to the processing of the user session, although the successful input had not yet taken place. The two-error bundle, dubbed MikroTrick, gave the administrative console without password knowledge, SSH key, and without completing authentication at all. Similar scenarios for the complete capture of RouterOS have already arisen before: in 2023, specialists described gaining full control over hundreds of thousands of potentially vulnerable MikroTik devices.
The new review also corrects the common confusion around CVE-2026-67276. The error really allowed you to bypass the SSH key check, but required to know the username and part of the data of the allowed RSA key. The MikroTrick chain, which operates without credentials, includes CVE-2026-67279 along with CVE-2026-86060.
The AI in the study was not used as a chatbot with a single request. CERT Polska has built a laboratory of 40 RouterOS CHR virtual machines, 39 status shots and 24 RouterOS releases from 6.43.11 to 7.25beta3. The agents independently controlled virtual machines, compared versions, disassembled binary files radar through radar2 and Ghidra, reconciled the behavior of SSH with RFC and systematically checked unusual transitions between protocol states. It was checking the re-exchange of keys before the end of authentication that helped to find the second part of the chain.
The danger was not theoretical. The earliest open attack logs are dated September 2, while the corrections came out on September 3. In several incidents there was an attempt to enter under the name -2, creating a privileged user ops and transmission of diagnostic data from the router. MikroTik recommends upgrading to at least 6.49.21, 7.23.4, 7.24.2 or newer version of the corresponding branch, close the SSH from untrusted networks, and check the configuration for unknown users, scripts and other changes.
In a detailed technical analysis, CERT Polska emphasizes that the speed of AI did not cancel the manual inspection. The specialists confirmed each hypothesis with repeated tests on clean systems, negative checks and comparison of several RouterOS issues. The main advantage of the agents was the ability to quickly go through the atypical states of a complex protocol and automate work that used to take much longer.
By the time of publication of the details, it became known that MikroTrick had already been used against real routers, and the number of potentially available devices from the Internet only in early September was estimated at more than 122 thousand. Therefore, the analysis of the update actually went simultaneously with the attacks that have already begun.
For MikroTik, such a scenario is particularly sensitive because of the role of routers on the network boundary. A few years ago, the company's compromised devices were already under the control of intruders years after the closure of the vulnerabilities and then fell into large botnets. One of the most famous examples is the Mēris botnet, which used long-hacked routers for subsequent attacks.
The story began on September 3, when MikroTik almost simultaneously released RouterOS 7.24.2, 7.23.4, 6.49.21 and 7.25beta3, calling the update important, but not revealing details. The urgency quickly attracted the attention of specialists, and the magazines of hacked devices that appeared in the network showed a strange picture: RouterOS first recorded the unsuccessful user's entrance -2, and then an account appeared in the same session ops with full rights. First details real attacks appeared almost immediately after the release of the corrections.
A comparison of the old and new builds showed that MikroTik added a username check before transmitting data to the internal program /nova/bin/login. The team of CERT Polska compared the change with the attacks logs and in an hour revealed CVE-2026-86060. The vulnerability allowed the specially formed username to influence the arguments of the service program and replace the privilege mask that RouterOS considered trusted.
One CVE to enter without a password was not enough. The second part of the chain was CVE-2026-67279 in the SSH server RouterOS. When the keys were re-agreed before the authentication was completed, the server could mistakenly proceed to the processing of the user session, although the successful input had not yet taken place. The two-error bundle, dubbed MikroTrick, gave the administrative console without password knowledge, SSH key, and without completing authentication at all. Similar scenarios for the complete capture of RouterOS have already arisen before: in 2023, specialists described gaining full control over hundreds of thousands of potentially vulnerable MikroTik devices.
The new review also corrects the common confusion around CVE-2026-67276. The error really allowed you to bypass the SSH key check, but required to know the username and part of the data of the allowed RSA key. The MikroTrick chain, which operates without credentials, includes CVE-2026-67279 along with CVE-2026-86060.
The AI in the study was not used as a chatbot with a single request. CERT Polska has built a laboratory of 40 RouterOS CHR virtual machines, 39 status shots and 24 RouterOS releases from 6.43.11 to 7.25beta3. The agents independently controlled virtual machines, compared versions, disassembled binary files radar through radar2 and Ghidra, reconciled the behavior of SSH with RFC and systematically checked unusual transitions between protocol states. It was checking the re-exchange of keys before the end of authentication that helped to find the second part of the chain.
The danger was not theoretical. The earliest open attack logs are dated September 2, while the corrections came out on September 3. In several incidents there was an attempt to enter under the name -2, creating a privileged user ops and transmission of diagnostic data from the router. MikroTik recommends upgrading to at least 6.49.21, 7.23.4, 7.24.2 or newer version of the corresponding branch, close the SSH from untrusted networks, and check the configuration for unknown users, scripts and other changes.
In a detailed technical analysis, CERT Polska emphasizes that the speed of AI did not cancel the manual inspection. The specialists confirmed each hypothesis with repeated tests on clean systems, negative checks and comparison of several RouterOS issues. The main advantage of the agents was the ability to quickly go through the atypical states of a complex protocol and automate work that used to take much longer.
By the time of publication of the details, it became known that MikroTrick had already been used against real routers, and the number of potentially available devices from the Internet only in early September was estimated at more than 122 thousand. Therefore, the analysis of the update actually went simultaneously with the attacks that have already begun.
For MikroTik, such a scenario is particularly sensitive because of the role of routers on the network boundary. A few years ago, the company's compromised devices were already under the control of intruders years after the closure of the vulnerabilities and then fell into large botnets. One of the most famous examples is the Mēris botnet, which used long-hacked routers for subsequent attacks.