MikroTik patches six RouterOS flaws as attackers exploit exposed SSH ports

This digest was compiled by AI from multiple sources — links to the originals are below.
MikroTik released RouterOS fixes on September 3, 2026, addressing six vulnerabilities, including two critical flaws that allow unauthenticated device takeover. CERT Polska found active exploitation dating back to at least September 2, before the patch existed. Over 122,500 MikroTik routers have SSH exposed to the internet, according to Shadowserver Foundation.
Key Facts
- MikroTik shipped RouterOS fixes on September 3, 2026, for six vulnerabilities, including two critical authentication-bypass and privilege-escalation flaws.
- CERT Polska found evidence of active exploitation dating back to at least September 2, 2026, before the patch was available.
- Shadowserver Foundation identified more than 122,500 MikroTik devices with SSH reachable on the open internet.
- The exploit chain, dubbed MikroTrick by CERT Polska, combines two flaws to take full control of a device without authentication.
- MikroTik recommends checking the Log section for a 'Flagged' status after upgrading, which indicates the device has been compromised.
The Vulnerabilities
MikroTik released RouterOS updates on September 3, 2026, addressing six security bugs, including two critical flaws. The release notes mention only an 'important security update' and provide no technical details. Security researchers reverse-engineered the patches using AI and identified the six vulnerabilities. CERT Polska named the exploit chain MikroTrick and warned that combining two of the flaws allows full device takeover without authentication.
Active Exploitation
CERT Polska found evidence of active exploitation dating back to at least September 2, 2026, indicating zero-day use before the patch. The Shadowserver Foundation reported over 122,500 MikroTik devices with SSH exposed to the internet. The highest numbers of exposed devices are in Brazil (11,300), the United States (7,100), Indonesia (7,100), the Czech Republic (6,300), and Ukraine (5,100). It is unclear how many of the exposed devices remain vulnerable after the patch.
Post-Update Checks
MikroTik's advisory states that RouterOS will check if a device has been compromised and set it to 'Flagged' status. Owners of Flagged devices should treat the router as compromised and follow a separate procedure. Even without a Flagged state, MikroTik recommends inspecting device configuration for unknown scripts, users, or suspicious settings. MikroTik sent a push notification through its app for the first time to alert users about the update.