MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network

Initial focus for our partnership with Motorola is a regular non-folding device

Initial focus for our partnership with Motorola is a regular non-folding device Source: Hacker News

Explain it to me like I’m ten

Explain it to me like I’m ten Source: Hacker News