# MikroTik Routers Vulnerable to Unauthenticated SSH Exploits

*Published September 7, 2026*
*Source: [https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html](https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/mikrotik-routers-vulnerable-to-unauthenticated-ssh-exploits) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Recent findings by CERT Polska reveal that attackers are exploiting MikroTik routers' SSH service, which is accessible from the internet, to gain unauthenticated full administrative control. This alarming security breach has been active since at least September 2, although details about the number of victims or the identity of the attackers remain undisclosed.

To combat this vulnerability, MikroTik has released security updates that address the issues in their RouterOS. Users are strongly advised to install these updates immediately and thereafter check for any unauthorized changes in configuration. The vendor emphasizes that default firewall rules on home devices should prevent public access to management ports, provided these rules have not been altered.

Until the necessary updates can be applied, CERT recommends disabling exposed services or limiting access to trusted management networks, focusing on services like SSH, WWW/WWW-SSL, and bandwidth tests. Furthermore, users should avoid making TLS connections or using RouterOS's built-in SSH clients from devices that have not been updated, as these measures only serve as temporary safeguarding against the broader set of vulnerabilities.

RouterOS includes a feature that flags devices if suspicious configurations are detected, disabling certain functions to reduce risk. After updating, users should check system logs and inspect for any unusual users or scripts. If any indication of compromise is found, it is crucial to preserve evidence before taking further recovery steps.

The vulnerability has been coined 'MikroTrick' by CERT, but the exact vulnerabilities and how they interconnect to allow administrative control have not been explicitly detailed. The timeline of releases and initial fixes suggests that the zero-day status of this exploit is still uncertain.
