MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Large Language Models Develop Novel Social Biases Through Adaptive Exploration

Large Language Models Develop Novel Social Biases Through Adaptive Exploration Source: Hacker News

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials