Skip to main content

MikroTik RouterOS "MikroTrick" Authentication Bypass Chain Seizes Devices Without Credentials (CVE-2026-67277 / CVE-2026-86060)

Scope: MikroTik RouterOS (All Versions Affected by Both CVEs, Prior to Latest Stable Release)

Severity: Red

CERT Polska documented an active exploitation campaign it named MikroTrick this week, in which unknown threat actors are chaining two critical MikroTik RouterOS vulnerabilities, CVE-2026-67277 and CVE-2026-86060, to seize full control of vulnerable devices without any authentication required, bypass all access controls, and establish persistent footholds on compromised routers used as a springboard for further attacks into connected networks. CISA added both flaws to its Known Exploited Vulnerabilities catalog with a federal deadline of September 13, 2026. MikroTik routers and switches are widely deployed across Ugandan ISPs, enterprise offices, universities, and government network infrastructure, making this a directly relevant and urgent advisory for the local environment. Organizations must update RouterOS to the latest stable version immediately, disable Winbox and API access from untrusted networks, and audit administrator accounts for any unauthorized additions.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.