Active exploitation of MikroTik RouterOS devices is underway, with attackers gaining full admin access via internet-exposed SSH—no authentication required. CERT Polska issued a warning on September 5, with confirmed attacks dating back to at least September 2. No victim count or attribution has been released yet.
Technical Breakdown – Attack Vector: Internet-facing SSH service on MikroTik routers (likely older or unpatched RouterOS versions). – Impact: Full administrative control over the device, enabling traffic interception, DNS hijacking, botnet recruitment, or pivot into internal networks. – No Authentication Required: Implies a critical authentication bypass or default credential abuse—CVE details pending or unconfirmed. – IOCs: None publicly available at this time. Monitor for unauthorized SSH sessions, unexpected config changes, or outbound connections from RouterOS devices.
Defense Immediately disable SSH access from the WAN interface. If remote management is required, restrict by source IP and use VPN or SSH key-only authentication. Update RouterOS to the latest stable version and audit for any unauthorized admin accounts or firewall rule changes.
Source: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
Source: r/SecOpsDaily · by /u/falconupkid