RouterOS Flaw Chain Grants Full Admin Access to Exposed MikroTik Devices

Two vulnerabilities in MikroTik RouterOS SSH were chained to allow full administrative takeover without credentials. CERT Polska named the chain MikroTrick, combining an SSH state-machine flaw and an argument-injection bug. Attack logs date back to at least September 2026.
The MikroTrick chain targets the SSH service within RouterOS, the operating system used by MikroTik networking equipment. By combining a flaw in SSH's state-machine handling with an argument-injection weakness, attackers can achieve complete administrative control without ever supplying credentials. CERT Polska identified the chain and observed exploitation attempts in logs reaching back to at least September 2026.
MikroTik devices are commonly deployed in small businesses and home networks, making exposed SSH interfaces a substantial attack surface. The unauthenticated nature of the takeover raises the stakes, as compromised routers could be redirected for traffic interception or leveraged as footholds for deeper network intrusion. The extended period of observed activity suggests the chain may have been actively used well before disclosure.
Organizations relying on MikroTik routers for edge connectivity could face serious disruption if the MikroTrick chain is exploited. Network administrators may need to audit exposed SSH services and apply patches promptly. For small businesses without dedicated security teams, the unauthenticated takeover risk could translate into data breaches or loss of network integrity. Home users with default configurations may also be exposed. The September 2026 attack timeline suggests threat actors may have already leveraged this chain, potentially affecting numerous networks before public awareness.