MikroTik RouterOS "MikroTrick" Chain Confirmed to Enable Full Administrative Takeover (CVE-2026-67279)
Scope: MikroTik RouterOS Version 7.x
Severity: Amber
CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities catalog on September 25, 2026, citing active exploitation, with a federal deadline of today, September 28, 2026. Security firm Bishop Fox has independently reproduced the full attack chain, dubbed MikroTrick, confirming that it grants complete administrative control over vulnerable RouterOS 7.x devices. The flaw works by combining two separate trust failures: an unauthenticated network connection is able to reach functionality that RouterOS should only expose to a user who has already logged in, and the login process then mistakenly treats data coming from that unauthenticated connection as if it came from a trusted, already-authenticated administrator. Researcher Emilio Gallegos, who worked on the analysis, described it as a case where a feature meant only for trusted local callers becomes a remote attack surface once an upstream component loses track of authentication state. MikroTik routers are widely used across Ugandan internet service providers, campuses, and small office networks, making this a broadly relevant advisory for the local environment. Organizations must update RouterOS to the latest available version immediately and restrict remote management access to trusted internal networks only.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.