MikroTik, a leading network equipment manufacturer, has released crucial patches for six vulnerabilities in its RouterOS software, urging all users to update their devices immediately. The company has identified two of these vulnerabilities, collectively called 'MikroTrick,' as being actively exploited by cybercriminals. These flaws allow attackers to bypass authentication protocols and gain full control over devices, posing significant security risks. CERT Poland has confirmed that the exploitation of MikroTrick involves a combination of vulnerabilities, specifically targeting devices with SSH services exposed to public networks.

The vulnerabilities in question include CVE-2026-67276, an SSH authentication bypass rated at a severity score of 9.2, and CVE-2026-86060, an SSH session privilege manipulation also rated at 9.2. Additionally, CVE-2026-67277, a memory disclosure and denial-of-service issue, holds a severity score of 8.8. Since at least September 2, hackers have been exploiting these vulnerabilities, creating unauthorized accounts named 'ops' and originating attacks from specific IP addresses.

To mitigate these threats, MikroTik advises users to upgrade their routers to the latest RouterOS versions, including 7.25beta3, 7.24.2, 7.23.4, or 6.49.21. These updates also address other vulnerabilities such as CVE-2026-67278, CVE-2026-67279, and CVE-2026-67281. A recent scan conducted by the Shadowserver Foundation identified over 120,000 MikroTik devices with publicly accessible SSH, emphasizing the urgency of applying these security updates. MikroTik also recommends blocking SSH access from untrusted sources and checking device logs for any suspicious entries marked as 'Flagged.'