# MikroTik router flaws allow takeover without a password

DevFeed: [MikroTik router flaws allow takeover without a password](<https://devfeed.tech/articles/mikrotik-router-flaws-allow-takeover-without-a-password-8440.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/mikrotik-routers-can-be-taken-over-without-password>)

Author: Pieter Arntz

Published: 2026-09-08T09:49:16Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [cve-2026-67276](<https://devfeed.tech/tags/cve-2026-67276.md>), [cve-2026-86060](<https://devfeed.tech/tags/cve-2026-86060.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [news](<https://devfeed.tech/tags/news.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Attackers are actively exploiting two MikroTik RouterOS flaws, dubbed MikroTrick, to bypass SSH authentication and escalate privileges on internet-exposed routers. The article recommends promptly installing RouterOS updates and restricting SSH and other remote-management access.

## Source excerpt

Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.