Pre-authentication means a flaw lets an attacker reach a vulnerable operation before the service verifies their identity. In the MikroTrick attack reported by CERT Polska, two RouterOS vulnerabilities were chained to gain full administrative privileges through SSH. The routers CERT Polska confirmed were attacked had SSH reachable from public networks; the flaw did not make every RouterOS device reachable from the internet.
How the MikroTrick attack worked
In its September 5, 2026 incident warning, CERT Polska confirmed active exploitation of a two-vulnerability chain it named MikroTrick. The chain targeted RouterOS devices with publicly reachable SSH. CERT Polska summarized the risk this way: “Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol.”
- CVE-2026-67279: The attacker used an unauthenticated SSH connection to reach session-channel handling before the normal authentication-to-channel transition. CERT Polska’s vulnerability records also describe unauthenticated file operations through SSH after a rekey.
- CVE-2026-86060: The attacker then exploited argument handling in the login path. In combination with the first flaw, this gave the resulting session full administrative privileges.
The sequence matters: the initial flaw exposed SSH handling before authentication, and the second flaw turned that access into administrative control. This is not a claim that every unauthenticated RouterOS issue has the same effect.
What “pre-authentication” means—and what it does not
Authentication is the step where a service checks a client’s identity, for example by verifying a password or cryptographic key. A pre-authentication vulnerability lets an attacker reach a sensitive operation before that check succeeds. “Unauthenticated” describes the attacker’s access state; it does not mean the service is automatically reachable from every network.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- hEX also known as RB750Gr3 is a five port Gigabit Ethernet router for locations where wireless connectivity is not required
- The device has a full size USB port. This new updated revision of the hEX brings several improvements in performance
- It is affordable, small and easy to use, but at the same time comes with a very powerful dual core 880MHz CPU and 256MB RAM
- IPsec hardware encryption (~470 Mbps) and The Dude server package is supported, microSD slot on it provides improved r/w speed for file storage and Dude
- Dimensions: 113x89x28mm; Storage size: 16 MB; Passive PoE (PoE in); PCB temperature monitor, Voltage monitor and Mode button
For MikroTrick, the important exposure condition was that SSH could be reached from the public internet. A vulnerability in a service that is disabled or restricted to trusted networks is not exposed to the same set of remote attackers, though access restrictions do not fix the underlying software flaw.
Authentication requirements and impacts differ by vulnerability. For contrast, MikroTik’s historical CVE-2018-115X advisory described web-server issues that required a known username and password and allowed an authenticated user to crash the www service. That is different from a pre-authentication route to administrative control.
Rank #2
- Wired Gigabit Router – 5x Gigabit Ethernet ports, 2.5G SFP, PoE-Out, USB, powered by RouterOS
How the disclosed RouterOS flaws differ
CERT Polska reported six RouterOS vulnerabilities in September 2026. The table separates the MikroTrick chain from other disclosed issues; “not stated” means the cited CERT Polska records do not establish that detail in the information summarized here.
| CVE | Authentication and exposed service | Reported effect or role | Active exploitation and fix information |
|---|---|---|---|
| CVE-2026-67279 | Unauthenticated SSH session-channel handling | Can enable unauthenticated file operations through SSH after a rekey; first vulnerability in the MikroTrick chain. | CERT Polska confirmed exploitation as part of MikroTrick. MikroTik’s September 3 advisory listed fixes in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21; check current vendor guidance for the applicable branch. |
| CVE-2026-86060 | SSH login-path argument handling; used after CVE-2026-67279 | Completes the MikroTrick chain by granting full administrative privileges. | CERT Polska confirmed exploitation as part of MikroTrick. The same initial MikroTik advisory listed fixes in 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21; confirm the right current release for the device’s branch. |
| CVE-2026-67276 | SSH public-key authentication. CERT Polska’s description says the attacker needs to know an authorized user’s name and RSA modulus. | A flaw in full RSA public-key comparison let an attacker supply a key with exponent one and forge a valid signature without the user’s private key. This is distinct from the MikroTrick chain. | Not identified as part of the confirmed MikroTrick chain. CERT Polska’s September 5 records list 7.24.2, 7.23.4 and 6.49.21 among fixes for applicable issues; the issue-specific branch mapping is not stated here. |
| CVE-2026-67277 | Unauthenticated bandwidth-test service issue | Could disclose uninitialized kernel memory or cause a restart. | Not identified as part of the confirmed MikroTrick chain. CERT Polska’s September 5 records list 7.24.2, 7.23.4 and 6.49.21 among fixes for applicable issues; the issue-specific branch mapping is not stated here. |
| CVE-2026-67278 | Certificate/RSA signature handling; authentication requirement is not stated here. | Malformed RSA signatures were accepted. | CERT Polska said the initial fix was incomplete: the later fixes were RouterOS 7.23.6 long-term and 7.24.3 stable. Do not treat the earlier listed release numbers as sufficient for this CVE. |
| CVE-2026-67281 | Unauthenticated WebFig issue | Could read files. | Not identified as part of the confirmed MikroTrick chain. CERT Polska’s September 5 records list 7.24.2, 7.23.4 and 6.49.21 among fixes for applicable issues; the issue-specific branch mapping is not stated here. |
Severity scores are not measurements of the chance that a particular device is exposed or compromised. CERT Polska assigned CVSS 9.2 to CVE-2026-67276 and CVE-2026-86060, and 8.8 to CVE-2026-67277. The incident information does not establish a population-wide count or percentage of affected devices.
What administrators should do
1. Restrict management access
MikroTik advises against leaving SSH open to untrusted networks. If remote management is necessary, limit access to trusted IP addresses or use a strong VPN such as WireGuard; do not expose management ports to the internet unnecessarily. Restricting access reduces exposure but does not replace applying the relevant fix.
2. Upgrade to the fix for the specific issue and branch
MikroTik’s September 3, 2026 advisory listed fixes in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21 and recommended upgrading. CERT Polska’s September 5 records list 7.24.2, 7.23.4 and 6.49.21 for applicable issues. These are not a universal version recommendation for every installation: select a current vendor release appropriate to the device’s branch and verify that it addresses the CVE in question. In particular, CVE-2026-67278 required the later 7.23.6 long-term or 7.24.3 stable fix because the earlier fix was incomplete.
Rank #4
- MikroTik RouterBOARD C52iG-5HaxD2HaxD-TC-US (US Version) hAP ax (WiFi6) Quad-Core IPQ-6010 864 MHz, RAM 1GB, RouterOS, License level 4 It's time to supercharge your home network with the Generation
- hAP ax has everything you might need in a primary home access point - and more
- Forget endless reviews and comparisons - this is the perfect device for 99% of homes
- Wireless signal is now stronger than ever
- Here are the two main ingredients of hAP ax's success: a state-of-the-art dual-band, dual-chain 4-4
3. Review the configuration for signs of unauthorized changes
After upgrading, inspect the configuration for unexpected users, scripts, scheduler tasks, proxy servers, tunnels, or other changes. MikroTik also advises checking for unknown scripts, users, or modifications and following its flagged-device instructions if the device is marked.
4. Treat a Flagged result as a warning, not a complete test
CERT Polska says its Flagged mechanism detects selected signs of unauthorized changes. A device without a Flagged marker is not thereby proven clean. If the router is flagged, treat it as potentially compromised and follow incident-response guidance rather than assuming a software update alone resolves the incident.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
Best Value
- W128339515
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

