TL;DR — MikroTik has patched CVE-2026-86060, a critical flaw in the SSH login path of its hugely popular RouterOS operating system that is already being abused in a chained attack researchers have named “MikroTrick.” Rated CVSS 9.2 under v4.0 (and 9.8 under CVSS v3.1) and classified as CWE-88 (Argument Injection), the bug lets a crafted username beginning with a dash trick RouterOS into reading its trusted policy mask from the wrong place — turning a low-value session into full administrative control of the router. Paired with an SSH signature-verification bypass (CVE-2026-67276), an unauthenticated attacker can take over an internet-exposed device outright. CERT Polska confirmed active exploitation from at least 2 September 2026 — before any patch existed — and CISA added the flaws to its Known Exploited Vulnerabilities catalog in mid-September. Shadowserver counts more than 122,500 RouterOS devices with SSH exposed online.
What Is the MikroTik RouterOS Vulnerability (CVE-2026-86060)?
MikroTik RouterOS is the Linux-based operating system that powers MikroTik’s enormous fleet of routers, switches and wireless gear — kit that sits at the edge of small businesses, ISPs, hosting providers and critical-infrastructure networks across the world. It is cheap, capable and everywhere, which is exactly why RouterOS flaws have a habit of turning into botnets and proxy networks. CVE-2026-86060 is a vulnerability in the way RouterOS handles usernames during SSH login: a username that begins with a disallowed character is misinterpreted as a command-line argument, letting an attacker manipulate the session’s trusted policy mask and escalate to full administrative rights.
CIRCL and the vendor rate the flaw at CVSS 9.2 under version 4.0, while several trackers list it at 9.8 under the older CVSS 3.1 scale — either way it is squarely Critical. It is classified as CWE-88 (Improper Neutralisation of Argument Delimiters in a Command, a.k.a. Argument Injection). The v4.0 vector, CVSS:4.0/AV:N/AC:L/PR:N/UI:N/VC:H/VI:H/VA:H, describes a network-reachable, low-complexity bug that needs no prior privileges and no user interaction, with total impact to confidentiality, integrity and availability of the device. The one caveat baked into the score (AT:P) is that success depends on the attacker reaching the SSH login helper — trivial for the 122,500-plus routers already exposing SSH to the internet.
How the CVE-2026-86060 Exploit Works
In plain terms: when you log in over SSH, RouterOS decides what you’re allowed to do based on a “policy mask” tied to your account. The login helper that sets this up doesn’t properly sanitise the username, so a username that starts with a dash gets treated as an option or file-descriptor argument rather than a plain name. By sending a crafted username such as -2, an attacker makes the helper read the trusted username and policy mask from the wrong file descriptor (PTY fd 2), and a session that should be read-only is instead handed full administrative policy.
On its own, CVE-2026-86060 is a privilege-escalation bug. The reason it is so dangerous is the “MikroTrick” chain: attackers pair it with CVE-2026-67276, a separate SSH authentication bypass in which RouterOS validates only the type and modulus of an RSA public key, not its exponent. Knowing a valid username and public modulus, an attacker can forge a working signature without the private key — getting a foot in the door unauthenticated, then using CVE-2026-86060 to become admin. The tell-tale signs are unmistakable in RouterOS logs, and defenders should hunt for them directly rather than for exploit code, which is deliberately not reproduced here:
# MikroTrick indicators in RouterOS / SSH logs
login failure for user -2 from <attacker-ip> via ssh
user added by ssh:-2@<attacker-ip>
# CERT Polska observed attacks from 82.192.72.4 and 103.102.31.18
# Hunt for an unexpected privileged account (commonly "ops") and unknown scripts/schedulers
Impact Nuance: “Most Configurations Are Not at Risk” vs 122,500 Exposed Routers
Here is where honesty matters more than headlines. MikroTik’s own advisory stresses that “most configurations are not at risk” and that home users with a default, locked-down setup face no immediate threat — because the attack requires the SSH service to be reachable by the attacker. That is a fair point: a router whose management interfaces are firewalled off from the internet is not exposed to this chain.
The problem is how many routers are exposed. The Shadowserver Foundation identified more than 122,500 internet-facing RouterOS devices with SSH open, concentrated in Brazil, the United States, Indonesia, the Czech Republic and Ukraine. For every one of those, the “you’d need SSH reachable” caveat is already satisfied. And RouterOS devices are not just any endpoint — they route traffic. A compromised router can be turned into a proxy or traffic-interception node, folded into a botnet, or used as a quiet pivot deeper into the network behind it. That is precisely the pattern seen in previous RouterOS mass-exploitation waves.
A username is supposed to say who you are. In RouterOS, a username that started with a dash could tell the router what you were allowed to do — and the answer it read back was “everything.”
Active Exploitation of CVE-2026-86060
This is confirmed in-the-wild exploitation, not a theoretical risk. CERT Polska reported that abuse of the MikroTrick chain was underway from at least 2 September 2026 — before MikroTik shipped a patch — and documented real attacks from the IP addresses 82.192.72.4 and 103.102.31.18, including the creation of a privileged ops account for persistence. MikroTik released fixed builds on 3 September 2026, CERT Polska published its technical write-up on 5 September, and CISA added CVE-2026-86060 (alongside CVE-2026-67277) to its Known Exploited Vulnerabilities catalog in mid-September 2026, setting a short remediation deadline for US federal civilian agencies under Binding Operational Directive 22-01 that has now passed.
The exposure is anything but hypothetical. The Shadowserver Foundation tracked more than 122,500 RouterOS devices exposing SSH to the internet, and security researchers were quick to publish detection guidance because the indicators are so distinctive. For defenders, the single most useful check is your device logs and user list: look for a failed or successful login for the user -2, any account you did not create (the ops account is a known marker), and unexpected scripts, schedulers or SOCKS/proxy settings that a router-borne implant would add.
Remediation & Mitigation: Patching RouterOS
Patch now — the fixed builds exist. Upgrade RouterOS to a patched release for your branch: 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), or 7.25beta3 (testing). MikroTik does not auto-update most devices, so on-premises operators must apply this themselves. If you cannot upgrade this instant:
- Take SSH off the internet. Restrict the SSH service (and WWW/WWW-SSL and bandwidth-test) to trusted management IPs only, or firewall them off entirely. MikroTik’s guidance is to manage the router over a VPN such as WireGuard rather than exposing ports — this alone breaks the attack path.
- Disable services you don’t use. Turn off the SSH and bandwidth-test services if they aren’t needed, and change the default SSH port only as defence-in-depth, not as a substitute for access control.
- Check the “Flagged” status. After upgrading, MikroTik’s advisory notes devices may show a flagged state indicating prior tampering — treat that as a signal to investigate, not clear.
If SSH was reachable from the internet on an unpatched build, assume compromise. Patching a device that was already exposed does not evict an attacker who added their own account or scripts:
- Audit users and config. Remove any account you did not create (watch for
ops), and review scripts, schedulers, SOCKS/proxy settings, firewall rules and DNS for unauthorised changes. - Rotate every credential the device held — admin passwords, SSH keys, VPN secrets, RADIUS and API tokens — because they must be considered exposed.
- Rebuild from a known-good configuration where compromise is confirmed rather than trusting a cleaned device, and hunt your wider network for the pivot the router may have enabled.
Related ZeroDayHub Coverage
Edge and network devices remain the softest, highest-value targets on the internet — reachable by design, and privileged over everything behind them. We saw the same story in our write-up of the Ubiquiti UniFi OS network takeover (CVE-2026-34908), where a flaw in widely deployed networking gear handed attackers control of the estate, and in the Cisco Secure Firewall Management Center authentication bypass (CVE-2026-20079), another internet-facing management plane turned into an attacker’s front door. Different vendors, one lesson: if it routes or guards your traffic and it’s reachable, it’s a target — patch it first and keep its management interfaces off the open internet.
Sources & Further Reading
- MikroTik — September 2026 RouterOS vulnerability advisory (fixed versions, mitigations)
- Industrial Cyber — CERT Polska alert: MikroTik RouterOS actively exploited in “MikroTrick” chain
- The Hacker News — CISA adds five actively exploited flaws (incl. MikroTik RouterOS) to KEV
- Cybernews — MikroTik RouterOS vulnerabilities expose 122,500 routers (Shadowserver data)
- Security Affairs — Your MikroTik router may already be compromised: look for SSH user “-2”
- Exploit-Intel — CVE-2026-86060 detail (CVSS 4.0 vector, CWE-88, affected/fixed versions)
ZeroDayHub reports on vulnerabilities for defensive purposes only. This article deliberately omits working exploit code, reproducing only the log indicators defenders need to detect and respond to the “MikroTrick” campaign.





Leave a Reply