MikroTik MikroTrick SSH exploit chain PoC goes public, now in CISA KEV

evilsocket · x · 2026-09-27

A public PoC is out for "MikroTrick", a MikroTik RouterOS exploit chain exploited in the wild since at least 2026-09-02, disclosed by CERT Polska and now listed in CISA KEV.

The chain:

Impact & fix: internet-facing MikroTik SSH can be taken over to a full admin console with no credentials and no user interaction. Patched in 7.23.4 / 7.24.2 / 6.49.21.

Detection: look for login failure for user -2 via ssh followed by user added by ssh:-2@…; after patching, hunt for suspicious ops users and Flagged indicators.

Original post →

More from Safety

Safety channel →