MikroTik Routers Compromised via Exposed SSH Access

Recent reports indicate that attackers are exploiting vulnerabilities in MikroTik routers, allowing unauthorized administrative access through their internet-exposed SSH service.

Recent reports indicate that attackers are exploiting vulnerabilities in MikroTik routers, allowing unauthorized administrative access through their internet-exposed SSH service. This issue was highlighted in a warning from CERT Polska on September 5, 2026, with confirmed attacks dating back to at least September 2.

Details of the Exploit

The vulnerability allows attackers to gain full control of affected MikroTik devices without needing authentication. CERT Polska’s advisory did not specify the number of victims or the identity of the attackers involved in these incidents. The attacks leverage the SSH remote-access service, which is accessible from the internet.

Affected Versions and Mitigations

MikroTik has released security updates to address the vulnerabilities. The affected RouterOS versions include:

  • RouterOS 6.0.0 to 6.49.21
  • RouterOS 7.0.0 to 7.23.4
  • RouterOS 7.24 to 7.24.2
  • RouterOS 7.25beta3 (development channel)

Users are advised to update to the following fixed versions:

  • RouterOS 6.49.21
  • RouterOS 7.23.5
  • RouterOS 7.24.2

Until updates can be applied, CERT recommends disabling exposed services or restricting access to trusted management networks, especially for SSH and other management interfaces.

Recommendations for Users

MikroTik’s guidance suggests checking for unauthorized configuration changes after applying updates. Users should also monitor their logs for signs of compromise, such as unexpected high-privilege accounts or unusual account-creation logs. If any signs of compromise are detected, CERT advises isolating the router from the network, preserving logs, and restoring factory settings using a verified configuration.

Uncertainties Surrounding the Vulnerability

The specific vulnerabilities exploited in these attacks have not been explicitly identified, and it remains unclear how they interact to allow administrative access. Additionally, the status of whether a fix was available prior to the attacks has not been confirmed, leaving the zero-day status of the vulnerabilities unverified.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 386