MIKROTIK released a patch in late August 2026 for a vulnerability that permits SSH authentication bypass, according to SANS Internet Storm Center diary editor Johannes Ullrich. The flaw is already being exploited, and attackers have reportedly added new accounts to affected devices to retain access even after they are patched. MikroTik’s update attempts to detect signs of compromise and mark devices with a “Flagged” status.
Ullrich advises organisations to assume affected devices have been compromised, rather than treating patching alone as sufficient, and directs administrators to MikroTik’s September 2026 security notice for details.
The diary does not provide a CVE identifier, affected RouterOS versions or exploitation figures. It also does not identify specific victims or independently document the attacks beyond the statement that exploitation is under way. Administrators responsible for MikroTik equipment should apply the vendor’s patch promptly, check whether the update reports a “Flagged” state, and investigate unexpected accounts or other evidence of persistence before considering the device recovered.
Because attackers may remain present after patching, organisations should follow the vendor’s remediation guidance and assess affected devices as potentially compromised.