ON
← Back to feed
MicroTrick: RouterOS vulnerabilities are actively exploited patch now
Germany💻 Technology5 hr. ago

MicroTrick: RouterOS vulnerabilities are actively exploited patch now

The article reports on a security vulnerability known as 'MikroTrick' affecting MikroTik RouterOS devices. Security researchers have identified six vulnerabilities, two of which can be combined into an attack chain allowing attackers complete control over affected devices without valid credentials, provided the SSH service is accessible from the internet. The Polish Computer Emergency Response Team (CERT Polska) has coordinated the disclosure of these flaws, and while MikroTik has released patches, administrators are advised to consider their devices potentially compromised and perform additional checks. The vulnerabilities include CVE-2026-67276 and CVE-2026-86060, both with a high CVSS score of 9.2. Affected versions of RouterOS include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21, with all prior versions being vulnerable if certain services are exposed. Administrators are urged to check for signs of compromise using indicators such as suspicious log entries or unauthorized users.

Advertisement

Go to the primary sources (4)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenter5 hr. ago
MicroTrick: RouterOS vulnerabilities are actively exploited patch now

The article reports on a security vulnerability known as 'MikroTrick' affecting MikroTik RouterOS devices. Security researchers have identified six vulnerabilities, two of which can be combined into an attack chain allowing attackers complete control over affected devices without valid credentials, provided the SSH service is accessible from the internet. The Polish Computer Emergency Response Team (CERT Polska) has coordinated the disclosure of these flaws, and while MikroTik has released patches, administrators are advised to consider their devices potentially compromised and perform additional checks. The vulnerabilities include CVE-2026-67276 and CVE-2026-86060, both with a high CVSS score of 9.2. Affected versions of RouterOS include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21, with all prior versions being vulnerable if certain services are exposed. Administrators are urged to check for signs of compromise using indicators such as suspicious log entries or unauthorized users.

Bias read (Center): The article presents a technical security issue without overt ideological or political framing. It focuses on cybersecurity vulnerabilities and provides factual information about the risks, available patches, and recommended actions for administrators. There is no indication of partisan bias or slan

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories