487/69 Monday, September 7, 2026
CERT Polska has issued a cybersecurity warning after detecting threat actors exploiting vulnerabilities in MikroTik routers exposed to the public internet through Secure Shell (SSH). The exploitation could allow attackers to gain full administrator-level control of affected systems without authentication. Initial reports indicate that the activity has been observed since September 2. Although the attacks target devices with management ports exposed publicly, home users who still use MikroTik’s default firewall configuration remain protected because the system automatically blocks external access to these ports. At this time, there are no confirmed figures on the number of affected users, and the threat actors behind the activity have not been identified.
Experts refer to the combined exploitation of the two vulnerabilities as MikroTrick. The issue affects multiple versions of RouterOS. According to the update table, affected versions include RouterOS 6.0.0 through versions earlier than 6.49.21, 7.0.0 through versions earlier than 7.23.4, and 7.24 through versions earlier than 7.24.2. Security fixes have already been released in versions 6.49.21, 7.23.5 for the long-term branch, 7.24.2 for the stable channel, and 7.25beta3 for development. Users who cannot update immediately should apply temporary mitigation by disabling services exposed to the public internet or restricting access to authorized management networks only, especially SSH, WWW/WWW-SSL, and bandwidth-test services. They should also avoid making TLS connections or using the built-in RouterOS SSH client from unpatched devices to reduce the risk of exploitation during this period.
After updating the operating system, administrators should review usage history and run device status checks to determine whether any abnormal warnings related to configuration files are present. They should also inspect user accounts, scripts, and unusual settings. If compromise is suspected, such as the creation of unauthorized high-privilege accounts or logs containing abnormal symbols, administrators should isolate the device from the network, back up configuration data and system logs for evidence, then perform a factory reset and rebuild the system using only trusted configuration files. Restoring a full system backup directly from a compromised device is not recommended, in order to maintain the highest level of network security.
Source: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
