Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers exploit unauthenticated SSH on MikroTik routers for admin control.
Summary
Attackers are gaining full administrative control of MikroTik routers by exploiting internet-exposed SSH services without authentication. CERT Polska issued a warning on September 5, with attacks dating back to September 2. MikroTik has released security updates for various RouterOS versions, and users are urged to install them immediately and check for unauthorized configuration changes.
Full text
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Swati KhandelwalSep 06, 2026Vulnerability / Network Security Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity. MikroTik's security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes. According to the vendor's default firewall explanation, home MikroTik devices block public access to management ports while their default firewall rules remain intact. The Hacker News checked CERT's affected RouterOS versions against MikroTik's listed fixes on September 6. Use the official RouterOS downloads for your update. Affected range reported by CERT Initial security fix Update guidance From 6.0.0 below 6.49.21 6.49.21 RouterOS 6 security release From 7.0.0 below 7.23.4 7.23.4 Use 7.23.5 on the long-term channel From 7.24 below 7.24.2 7.24.2 Stable channel security release No development range listed in CERT’s disclosure 7.25beta3 Development channel fix The 7.23.5 regression fix addresses an IPv6 DHCP (Dynamic Host Configuration Protocol) problem introduced in 7.23.4 while retaining the security update. Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test. It also advises against initiating Transport Layer Security (TLS) connections or using RouterOS's built-in SSH clients from an unpatched device. These temporary restrictions cover the broader set of vulnerabilities and do not replace the update. MikroTik's Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration. RouterOS disables those entries and restricts certain functions. After updating, check the logs and run /system/device-mode/print to inspect that status. Even without a warning, inspect the configuration for unknown users, scripts, and other unrecognized changes. CERT also points to unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@ as signs to investigate. If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis. Isolate the router from the network and preserve its logs and configuration before resetting it. CERT’s preservation guide in Polish explains how to export and download the files. Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device. Change passwords, keys and other secrets in use. CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT's warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control. The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT’s attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified. The Hacker News has contacted CERT Polska and MikroTik for comment. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE MikroTik, network security, Router hacking, Vulnerability ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control
Indicators of Compromise
- malware — MikroTrick