MikroTik routers are actively being exploited through a vulnerability chain dubbed "MikroTrick," which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). This allows attackers to gain full administrator control over internet-exposed devices with SSH enabled. Exploitation began as early as September 2nd, prior to the release of patches. Users are urged to update to the latest stable versions and check logs for indicators of compromise, such as failed SSH logins with the username "-2" or the creation of an "ops" user account.

Photo: Deavmi (CC BY-SA 3.0) via Wikimedia Commons
MikroTik has issued an urgent advisory for its RouterOS, confirming active exploitation of a critical vulnerability chain, dubbed "MikroTrick," that allows unauthenticated attackers to gain full control of devices with SSH exposed to the internet. The company released patches on September 3, 2026, but evidence suggests exploitation began as early as September 2, making it a zero-day event.
The MikroTrick attack chain leverages two of six vulnerabilities identified by CERT Polska: CVE-2026-67276 (CVSS 9.2), an SSH authentication bypass, and CVE-2026-86060, an SSH session privilege escalation. The authentication bypass flaw allows an attacker who knows a valid username and the public part of an RSA key to forge a key and log in without the corresponding private key. When combined with the privilege escalation, this grants full administrative access to the device.
MikroTik has released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, 7.23.5, and 6.49.21. Users are strongly advised to update their devices immediately. CERT Polska and cybersecurity researchers have stressed that any MikroTik router with SSH accessible from the internet should be considered compromised until proven otherwise.
Observed attacks have originated primarily from the IP address 82.192.72[.]4, hosted by Leaseweb, which has been seen serving a MIPS build of BusyBox 1.16.1 along with Python scripts named `ftpsrv.py`, `launch.sh`, and `serve.py`. Another IP, 103.102.31[.]18, has also been linked to the campaign.
Defenders can identify potential compromises by examining router logs for specific indicators. A key sign of attempted exploitation is the appearance of the username "-2" in failed SSH login attempts. This is not a valid account and should not appear in normal logs. Successful attacks will show entries in `/system history` such as `ssh:-2@IP` followed by actions like creating new users, adding SSH keys, modifying firewall rules, or enabling proxy or tunnel services. The creation of an account named "ops" is another confirmed indicator of compromise.
It is important to note that the absence of "-2" login failures in current logs does not definitively mean a device is safe, as logs may have been rotated or cleared. Any configuration change associated with the "-2" user, particularly those related to user management, SSH keys, scripts, schedulers, services, firewall rules, proxies, tunnels, or packet sniffing, should be treated as a confirmed compromise unless it was part of an authorized security test.
MikroTik took the unusual step of sending push notifications through its official mobile app to alert users about these critical vulnerabilities, highlighting the severity of the situation. While devices with MikroTik's default firewall configuration that do not expose SSH to the public internet are likely protected, any device with SSH reachable from untrusted networks requires immediate patching and inspection.

Attackers are employing a sophisticated phishing technique that leverages invisible Unicode characters to bypass email security filters. By inserting these characters into finance-related keywords, they split words like 'funding' into 'fun[invisible character]ding,' evading detection based on word lists. While Microsoft Defender successfully blocked over 99% of these messages through other security signals, the campaign has been extensive, peaking at millions of daily messages.

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board […]

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

A critical pre-authentication SSRF vulnerability in SonicWall SMA1000 appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.