CERT Polska found the MikroTik flaws with AI agents, and wrote down what the agents could not do
2026-09-14Security
The six RouterOS vulnerabilities behind the MikroTrick chain came out of an agent-driven laboratory running two OpenAI models. The technique that worked was modelling protocols as state machines and breaking the order of the steps, which is exactly the shape of the bugs. Meanwhile CISA's catalogue lists two of the six, and one of them is not in the chain.