Attackers Hijack MikroTik Routers Via Internet-Exposed SSH
Attackers are gaining full administrative control of MikroTik routers whose SSH service is reachable from the internet, with no authentication required, according to an attack warning from CERT Polska published 5 September 2026. Successful attacks date to at least 2 September 2026; no victim count or attacker identity had been published as of 6 September.
Summary
MikroTik's security update fixes the issue in RouterOS 6.49.21, 7.23.4, 7.24.2 (and 7.23.5 on the long-term channel to resolve a regression), with no development-channel bypass listed in CERT's disclosure. CERT recommends immediate installation followed by a check for unauthorised configuration changes. Home devices with MikroTik's default firewall rules intact are not exposed, because public access to management ports is blocked by default. The episode underscores the ongoing risk from internet-exposed management services on edge and network devices.
Impact
- Full unauthorised administrative control of affected RouterOS devices where SSH is exposed to the internet
- Routers can be repurposed for lateral movement, traffic interception or resilient botnet/relay infrastructure
- Internet-exposed edge infrastructure remains a first-order intrusion vector across enterprise and service-provider environments
Sector
Global (Macro)
Sources
- The Hacker News โ Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- raw/digests/Cyber-Digest-2026-09-07.md