Security1 publisher3 min readPublished
CERT Polska's MikroTrick chain turns a known username and a public key into unauthenticated administrator access on any RouterOS box with SSH open. The confirmed traces are a login named -2 and an account called ops.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CVE-2026-67276 is a key-verification bug. RouterOS checks an RSA public key in a way that lets an attacker who already knows a valid username and the public half of that user's key mint a fake key and authenticate without ever holding the private half [6]. CVE-2026-86060 then lifts that session to administrator, and the pair yields full admin on any internet-exposed device with SSH enabled [5][7]. What the material does not explain is how the operators are collecting username-and-public-key pairs at scale. That step is the open question for MikroTik and CERT Polska.
The timing is what makes triage urgent here. Costin Raiu puts first exploitation at September 2 and calls the chain a 0day, reading the timing as someone knowing the patches were about to drop [9]. Logs on a Polish security forum and CERT Polska's own confirmed cases both date to at least September 2 [10]. That is one day ahead of the fixes and three days ahead of the public advisory [22].
Patching closes the door but does not remove whoever already walked through it. The forensic sequence starts with a failed login under the username -2, which is not a valid account and has no business in a normal log [13], then an entry in /system history reading ssh:-2@<IP> followed by a configuration action: a new user, an added SSH key, a changed firewall rule, a proxy or tunnel switched on [14]. Raiu's rule is to treat any -2 entry attached to such an action as confirmed compromise unless an authorised security test produced it [15]. His second rule is the one that matters for anyone with thin log retention, because he warns that absent -2 failures prove nothing when logs roll over or get cleaned [16]. The hunt therefore lands on config state, not history.
So far the infrastructure behind this stays limited. Most observed attacks came from one Leaseweb address, 82.192.72.4, which staged a 2010 MIPS busybox build identical to the official BusyBox 1.16.1 precompiled binary alongside ftpsrv.py, launch.sh and serve.py; a second address, 103.102.31.18, is also linked to the campaign [11]. Three of those four files had no VirusTotal detections at the time of writing [12], so signature blocking is not carrying the load here.
Raiu also tried to reproduce the chain with four AI tools. Astra declined on safety grounds and suggested he apply for cyber verification, while Sol, Daybreak Blue and GLM-5.3 were willing and none of them completed a working implementation [17]. From that gap he estimates one to two days before a working proof of concept is public on GitHub [18]. It is one researcher's estimate, and a PoC changes who can join a campaign that is already running at scale from a single IP [9][11].
MikroTik pushed notifications through its own mobile app for this round, which CERT Polska flagged as a first for the company [19]. That fits the install base: these devices run for years with little attention, and the ones that have missed updates for years are the ones that will still be exposed when the next flaw lands [21].
Ranked by verification strength, evidence, and original report placement.
CERT Polska issued an advisory on September 5, 2026 titled "Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended."
Costin Raiu published a detailed technical breakdown of the active exploitation on Medium on September 5, 2026.
CERT Polska says it identified and coordinated disclosure of six vulnerabilities in MikroTik RouterOS, and that combining two of them lets an attacker take full control of a device without authentication if it supports remote access over SSH; it named the chain MikroTrick.
CVE-2026-67276 is an SSH authentication bypass with a CVSS score of 9.2.
CVE-2026-67276 stems from how RouterOS verifies RSA public keys: an attacker who knows a valid username and the public part of that user's RSA key can create a fake key and log in without the private key.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two named primary accounts, no second check
The checkable material is genuinely checkable: CVE numbers, a CVSS score, exact firmware builds, two IP addresses and three SHA-256 hashes, with CERT Polska and Raiu quoted rather than paraphrased. The weakness sits in corroboration. No second newsroom has tested the 2 September timeline, MikroTik says nothing in its own words, and three of the four attacker files had no VirusTotal detections when the analysis went out, so scanners were not yet backing any of it up.
Fixes out across every branch, uptake unmeasured
MikroTik moved fast and broadly, patching four RouterOS branches inside two days and reaching users through mobile push alerts it had never used for this before. The other half of adoption is simply absent: nobody says how many RouterOS boxes answer SSH from the internet, how many have taken the update, or how many confirmed compromises CERT Polska holds. Attacks are described as happening at scale while the only quantities on offer are two source addresses and one account name.
Guidance runs a little ahead of the counts
Assume-compromised is a defensible posture when the chain needs only a username and a public key and a national CERT has confirmed successful intrusions. The stretch is in the scope: the headline advice reaches every exposed device while observed activity traces mostly to a single Leaseweb address, and the one-to-two-day window before a public proof of concept is quoted with a precision that one round of tool testing cannot support. Security Affairs does pull back at the end, noting that devices behind the default firewall are likely protected.
Credibility to gain, not product to sell
A national CERT publishing coordinated-disclosure findings has no product riding on the story, and MikroTik's only contribution is a version list rather than positioning. The mild pressures are worth naming anyway: being first to document an in-the-wild zero-day builds a researcher's standing, and Security Affairs signs off with its own social follow links, which is the ordinary economy of a security blog rather than a distortion of the findings.
One relay of a single fast-moving day
Most operational numbers here are pinned to the moment of writing: the detection counts, the proof-of-concept window, the observed source addresses. One publisher is carrying all of it roughly a day after the advisory. The structural facts should hold up, meaning the CVE pair, the key-verification defect and the patched build list; the picture of who is attacking from where was drawn on 5 and 6 September and will have moved since.
security
Community maps in MECCHA CHAMELEON could write files anywhere on a player's disk1 publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 publisher
build
The judge went synthetic first, which tells you which part of your pipeline is next1 publisher
build
PyInstaller exits zero, then the real work starts: notarization traps that report success1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026