MikroTik MikroTrick SSH exploit chain PoC goes public, now in CISA KEV
evilsocket · x · 2026-09-27
A public PoC is out for "MikroTrick", a MikroTik RouterOS exploit chain exploited in the wild since at least 2026-09-02, disclosed by CERT Polska and now listed in CISA KEV.
The chain:
- CVE-2026-67279 (CVSS 6.9): auth bypass — a pre-auth rekey request drops the server's "must be authenticated" gate
- CVE-2026-86060 (CVSS 9.2): privilege escalation — /nova/bin/login treats a dash-led username as a file descriptor and reads a replacement identity and policy mask from it; an all-ones mask yields full admin
- An unnamed state bug leaves a rejected username pending in session state, required for step one
Impact & fix: internet-facing MikroTik SSH can be taken over to a full admin console with no credentials and no user interaction. Patched in 7.23.4 / 7.24.2 / 6.49.21.
Detection: look for login failure for user -2 via ssh followed by user added by ssh:-2@…; after patching, hunt for suspicious ops users and Flagged indicators.
More from Safety
- Single neuron sufficient to bypass safety alignment in LLMs, paper finds — amplifiedamp · 2026-09-27
- Interpretability researcher: sandbagging signals from probes would block model deployment — thebasepoint · 2026-09-27
- Debate: NLAs as metamodels could surface hidden motives like deleting files to dodge graders — thebasepoint · 2026-09-27
- OpenAI admits 53 user-uploaded images leaked to image-hosting sites, questioned on user notification — AnkaReuel · 2026-09-27
- Petabytes of agent logs nobody reads: researchers warn of AI oversight collapse — birchlse · 2026-09-27
- Legal scholar debunks viral 'play Disney music to beat creepshots' advice — technollama · 2026-09-27