MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Linked advisories
- CVE-2026-67279MikroTik RouterOS — Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- CVE-2026-67279MikroTik RouterOS: Mehrere Schwachstellen
- CVE-2026-67279RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated c…
- CVE-2026-86060MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login
- CVE-2026-86060mikrotik routeros: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CVE-2026-67279mikrotik routeros: Improper Enforcement of Behavioral Workflow
More on MikroTrick
Source: https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
ID