← Back to Tech & Science

Global Cyberattack Targets MikroTik Routers via Critical Unauthenticated Flaws

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WARSZAWA — A coordinated wave of cyberattacks is currently targeting internet-exposed MikroTik RouterOS devices worldwide, exploiting two critical vulnerabilities that allow attackers to seize full control of the systems without requiring any authentication. The campaign, identified by security researchers as the 'MikroTrick' attack chain, poses an immediate threat to network infrastructure globally.

CERT Polska, Poland's national computer emergency response team, issued a high-priority alert on September 6, 2026, confirming that active exploitation is underway. The attacks leverage two specific flaws in MikroTik RouterOS software: CVE-2026-67276 and CVE-2026-86060. When chained together, these vulnerabilities enable remote attackers to bypass login screens entirely, granting them administrative privileges over affected routers once they are connected to the public internet.

Costin Raiu, a prominent security researcher who has been tracking the incident, stated that the exploitation is automated and rapid. The attack chain allows malicious actors to install backdoors, redirect traffic, or use compromised devices as part of larger botnets for distributed denial-of-service operations. Because the vulnerabilities do not require valid credentials to exploit, any MikroTik device with a default or misconfigured firewall rule exposing the management interface is at risk.

MikroTik, the Latvian manufacturer known for its widely used networking equipment in enterprise and residential settings, has acknowledged the severity of the situation. The company has released emergency firmware updates designed to patch both CVE-2026-67276 and CVE-2026-86060. Network administrators are urged to apply these patches immediately or isolate affected devices from the internet until remediation is complete.

The scale of the exposure remains a primary concern for cybersecurity agencies. While CERT Polska has confirmed the active nature of the attacks, the total number of compromised devices has not yet been quantified. The vulnerabilities affect a broad range of RouterOS versions, impacting millions of units deployed across telecommunications providers, educational institutions, and small businesses globally.

Security experts warn that the window for remediation is closing as automated scanning tools likely identify vulnerable targets within minutes of them coming online. The 'MikroTrick' campaign represents a significant escalation in router-based attacks, moving beyond simple credential stuffing to direct code execution via unauthenticated entry points.

As organizations rush to patch their infrastructure, questions remain regarding the identity of the threat actors behind the campaign and whether any data has already been exfiltrated from compromised networks. CERT Polska continues to monitor traffic patterns for signs of further exploitation, while researchers work to determine if additional vulnerabilities are being prepared for future use.

Discussion

0 / 2000