Network administrators managing MikroTik routers must apply an urgent security patch immediately to prevent a complete system takeover. A critical chain of two vulnerabilities, tracked as "MikroTrick," is being actively exploited to gain root-level control of internet-facing devices without any authentication.

The attack, documented by CERT Polska and detailed by The Hacker News, chains two separate flaws in the RouterOS SSH login process. The first, CVE-2026-67279, is a state-machine flaw in the SSH implementation. The second, CVE-2026-86060, is an argument-injection bug. When combined, they allow an attacker to connect to the SSH service and execute arbitrary commands with root privileges, bypassing all password and key-based authentication.

Malicious activity leveraging this chain has been observed since at least late August 2026, confirming it is a present and active threat. The risk is severe for any router with its SSH management interface exposed to the public internet.

The definitive solution is to update the router's operating system. Administrators should upgrade to RouterOS version 7.21.2 or 7.22 Beta 3, which contain patches for both vulnerabilities. For devices that cannot be patched immediately, the recommended interim measure is to disable the SSH service or strictly limit management access to trusted internal networks using firewall rules.

This incident starkly illustrates the compounded danger of vulnerability chaining. Individual flaws that might otherwise be deemed moderate can combine to create a pathway for complete system compromise, a critical lesson for securing network infrastructure.


管理 MikroTik 路由器的網絡管理員必須立即應用緊急安全補丁,以防止系統被完全接管。被追蹤為「MikroTrick」的兩個關鍵漏洞鏈,正被積極利用以取得面向互聯網設備的根級控制權,且無需任何認證。

CERT Polska 記錄並由 The Hacker News 詳述的此攻擊,利用了 RouterOS SSH 登錄過程中的兩個獨立缺陷。第一個是 CVE-2026-67279,屬於 SSH 實現中的狀態機缺陷。第二個是 CVE-2026-86060,屬於參數注入錯誤。兩者結合,使攻擊者能夠連接至 SSH 服務,並以 root 權限執行任意命令,繞過所有密碼及密鑰驗證。

自至少 2026 年 8 月底起,已觀測到利用此漏洞鏈的惡意活動,證實其為當前且活躍的威脅。對於任何將 SSH 管理介面暴露於公共互聯網的路由器,風險極為嚴重。

最終解決方案是更新路由器操作系統。管理員應升級至 RouterOS 版本 7.21.2 或 7.22 Beta 3,其中包含針對兩個漏洞的補丁。對於無法立即打補丁的設備,建議的過渡措施是停用 SSH 服務或透過防火牆規格將管理訪問嚴格限制至受信任的內部網絡。

此事件清晰地闡明了漏洞鏈所帶來的複合危險。單獨可能被評為中等程度的缺陷,結合起來卻可能成為完全系統入侵的途徑,這是鞏固網絡基礎設施安全的重要一課。

新聞來源 / Original News Source