Threat Intelligence

MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed

The Hacker News · 6 Sept 2026
Key Takeaway If you run MikroTik routers, patch to the latest RouterOS version immediately and restrict remote management access to trusted networks only.

Polish national cybersecurity body CERT Polska has issued a warning that attackers are hijacking MikroTik routers by exploiting the Secure Shell (SSH) remote-access service when it is exposed to the internet, gaining full administrative control without needing a password. The attacks have been confirmed since at least September 2, though the number of victims and the identity of the attackers remain unknown.

MikroTik has released fixed versions of its RouterOS software, and CERT Polska recommends installing these updates immediately, then checking devices for unauthorized configuration changes. Home MikroTik devices with default firewall settings intact are not exposed to this issue, as public access to management ports is blocked by default. Businesses using custom configurations should verify their exposure urgently.

Until updates are applied, CERT advises turning off exposed management services, particularly SSH, WWW/WWW-SSL, and bandwidth-test tools, or restricting access to trusted internal networks only. After updating, administrators should review logs for signs of compromise, including unexpected privileged accounts or suspicious login entries, and check the device's flagged status using built-in RouterOS commands. If compromise is suspected, evidence should be preserved before any remediation steps are taken.

MikroTik RouterOS SSH vulnerability network security patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.