Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Swati KhandelwalSep 06, 2026Vulnerability / Network Security

Recent reports indicate that attackers are taking advantage of vulnerabilities in MikroTik routers, specifically targeting the Secure Shell (SSH) remote-access service. This exploit allows unauthorized access without the need for authentication, as highlighted in CERT Polska’s warning issued on September 5.

While the exact number of affected users and the identities of the attackers remain undisclosed, successful attacks have been traced back to at least September 2. To address this issue, MikroTik has released security updates for affected RouterOS versions, aiming to mitigate the observed attacks and prevent further exploitation.

It is crucial for users to promptly install the recommended fixes and verify for any unauthorized configuration changes post-installation. Additionally, MikroTik’s default firewall settings are designed to block public access to management ports, offering an added layer of protection.

For users seeking to update their systems, it is advised to refer to the official RouterOS downloads provided by MikroTik, ensuring a secure and reliable update process. The article also emphasizes the importance of checking logs and system status post-update to detect any anomalies or unauthorized access.

As a precautionary measure, CERT suggests limiting access to exposed services and management networks, particularly for services like SSH and WWW-SSL. Temporary restrictions on TLS connections and usage of RouterOS’s SSH clients from unpatched devices are also recommended to mitigate risks.

In case of suspected compromise, CERT outlines a series of recovery steps, including isolating the affected router, preserving logs and configurations, and resetting the device to factory settings before implementing a verified configuration.

While the exact nature of the vulnerabilities exploited, dubbed as MikroTrick by CERT, remains undisclosed, ongoing collaboration between security experts and vendors like MikroTik is essential to address such threats effectively.

For further updates and detailed information on the security patches released by MikroTik, users are advised to stay informed through official channels and prioritize system security to safeguard against potential cyber threats.