ATTACKERS are exploiting MikroTik routers’ SSH remote-access service that is reachable from the internet to gain full administrator access without authentication. CERT Polska issued an attack warning on 5 September 2026 describing this chain, with evidence dating back to at least 2 September. The Hacker News has since reviewed CERT’s warning but could not identify the victims or attacker identities.
MikroTik and CERT Polska say the observed attacks are mitigated by the vendor’s security updates, which fix RouterOS releases and block the specific exploitation observed.
CERT Polska lists affected RouterOS versions and corresponding fixes, and MikroTik’s guidance emphasises that home devices should by default block public access to management ports, with firewall rules intact. CERT advises immediate installation of the patched releases and then checking for unauthorised configuration changes.
Until updates are applied, recommendations include turning off exposed services or restricting SSH to trusted networks, and avoiding TLS connections or RouterOS built-in SSH clients from unpatched devices. Post-update, users should review logs and run diagnostic checks for suspicious accounts or changes, such as highly privileged accounts or unusual ssh:-2@ entries.
CERT labels the observed exploit chain as MikroTrick, though the two underlying vulnerabilities forming the chain are not explicitly identified in the public disclosures. If compromise is suspected, CERT instructs isolating the router, preserving logs, restoring from a trusted configuration, and changing passwords and secrets.