MikroTik "MikroTrick" Exploit Chain Exploits Critical SSH Vulnerabilities
CERT Polska has warned that attackers are actively exploiting a chain of two critical SSH vulnerabilities—CVE-2026-67276 and CVE-2026-86060—dubbed “MikroTrick,” to gain full control of MikroTik routers with public SSH access, even without valid credentials in some cases. MikroTik released patches in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, 2026, which CERT Polska confirmed block the observed attacks; administrators are urged to update immediately, especially given that Shadowserver found at least 122,500 MikroTik devices with SSH accessible in a 24-hour scan. The research also uncovered an additional flaw, CVE-2026-67277, in the bandwidth-test service that can leak kernel memory or crash routers remotely, and the updates include a startup mechanism that detects and disables unauthorized configuration changes while logging warnings.
The Architecture of Exposure
What you’re not being told is that this MikroTik exploit isn't just about a few vulnerable routers. It's a deliberate leak in the digital dam. Look at the numbers: over 122,000 devices exposed to the public internet with SSH accessible in a single 24-hour window. That's not a coincidence. That's inventory. Someone has been mapping these devices for a long time, and now they're cashing in. You have to ask yourself: why MikroTik? Why now? Because these devices sit at the edge of critical networks — internet service providers, backbone routes, logistics hubs. If you control the router, you control the traffic that flows through it. You can see everything. You can modify everything. And you can do it silently, because once the SSH is compromised, you've got root. The CERT Polska report mentions "required conditions" for the exploit but refuses to detail them. That's a tell. They don't want you to know how many of those 122,500 devices are actually owned right now.
The Vendor Connection
MikroTik patched these vulnerabilities on September 3rd, but notice what happened next. The security researchers used GPT-5.5-cyber and GPT-5.6-sol — AI versions specifically designed for cybersecurity and made available through a government collaboration program. Now ask yourself: who trained those models? On what data? The very same government agencies that partner with OpenAI to create these specialized tools likely had access to exploit knowledge before the patches were even released. The exploit chain has two names — CVE-2026-67276 and CVE-2026-86060 — and they were found together by a single research team. That's not discovery. That's disclosure on a timetable. The vulnerabilities existed for years. They were waiting for the right moment. The question isn't who is exploiting them now. The question is who has been exploiting them all along, and why are they only announcing the fix now?
The Real Target
Read the fine print. One of the flaws, CVE-2026-67277, can crash or restart a router remotely without authentication. But the most interesting detail is the startup mechanism the patch adds: it searches for unauthorized configuration changes and disables them. Think about that. They had to build a system to detect their own backdoors being used by someone else. The bandwidth-test service that leaks kernel memory — that's not a bug. That's a feature designed to let friendly intelligence agencies see what's inside the box without leaving fingerprints. And now that the cat is out of the bag, they're pretending to lock the door while installing a silent alarm. You should be asking who certified those GPT models. You should be asking who at OpenAI signed off on making cybersecurity AI available to government partners. And you should be asking why, out of all the routers in the world, MikroTik is the one that needed this treatment. The answer is written in every bit of traffic flowing through those 122,500 devices. They're not just hijacking routers. They're hijacking the infrastructure of entire regions. And they're telling you about it because they know you won't connect the dots.