MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

American Airlines mechanic Azriel “Al” Blackman has died, aged 100

American Airlines mechanic Azriel “Al” Blackman has died, aged 100 Source: Hacker News

Show HN: TeXbrain, a LaTeX editor that runs pdfTeX in the browser via WASM

Show HN: TeXbrain, a LaTeX editor that runs pdfTeX in the browser via WASM Source: Hacker News

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully