Successful attacks date to at least September 2, according to CERT Polska’s advisory — and the attackers are exploiting internet-reachable SSH on MikroTik routers to gain full administrative control without any authentication.
CERT Polska’s warning and the observed timeline
On September 5 CERT Polska published an attack warning describing active exploitation of MikroTik routers whose Secure Shell (SSH) services were reachable from the internet. The advisory reports that attackers were able to obtain full administrative control without authentication. CERT Polska’s timeline places successful attacks at least as early as September 2. A follow-up review by The Hacker News on September 6 found no published victim count and no public attribution to a specific attacker.
Attack vector: internet‑exposed SSH and recommended temporary mitigations
CERT Polska says the active exploitation leverages SSH access that is reachable from the public internet. Until affected devices are patched, the agency recommends disabling exposed services or restricting them to trusted management networks, naming SSH, WWW/WWW‑SSL and bandwidth‑test in particular. CERT also advises administrators not to initiate Transport Layer Security (TLS) connections or use RouterOS’s built‑in SSH clients from an unpatched device. Those temporary controls are intended to reduce immediate exposure but are not a replacement for the security update.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageMikroTik’s fixes, versions to install, and the 7.23.5 note
MikroTik has published a security update and lists the RouterOS releases that contain the fixes. CERT Polska says those fixes prevent the observed attacks and recommends immediate installation followed by inspection for unauthorized configuration changes. The Hacker News checked CERT’s list of affected RouterOS versions against MikroTik’s published fixes on September 6 and emphasized using the official RouterOS downloads for updates.
The vendor’s 7.23.5 release includes a regression fix addressing an IPv6 DHCP problem introduced in 7.23.4 while retaining the security update. Separately, MikroTik’s 7.25beta3 release notes carry a September 2 changelog date and initial fixes were announced on September 3; The Hacker News compared those dates with CERT Polska’s attack timeline and concluded those dates do not establish whether a fix was publicly available before the attacks, so the zero‑day status remains unverified.
Detection signals: 'Flagged' status, logs and indicators to inspect
MikroTik’s documentation explains that RouterOS can flag a device when startup checks detect suspicious configuration entries; flagged entries are disabled and certain functions are restricted. After installing updates, CERT Polska advises checking the logs and running /system/device-mode/print to inspect the Flagged status. Even without a Flagged warning, administrators should inspect the configuration for unknown users, unexpected scripts and other unrecognized changes.
CERT points to specific signs to investigate: unexpected highly privileged ops accounts and account‑creation log entries containing ssh:-2@. If the warning, logs or configuration suggest compromise, CERT instructs administrators not to clear the Flagged status before preserving evidence and completing analysis.
Recovery steps CERT Polska prescribes
- Isolate the router from the network and preserve logs and configuration before resetting the device; CERT’s preservation guide (in Polish) explains how to export and download the files.
- Restore factory settings and rebuild the device using a trusted, verified configuration; do not blindly restore a full backup from the potentially compromised device.
- Change passwords, keys and other secrets in use after rebuilding.
CERT Polska labels the reported two‑flaw combination “MikroTrick.” Neither CERT’s warning nor the accompanying vulnerability disclosure—when compared by The Hacker News on September 6—explicitly identifies which two flaws form the observed chain or details how they combine to yield administrative control.
What this means for security teams, procurement leaders, and end users
- Security teams: Prioritize immediate inventory of internet‑facing MikroTik devices, verify RouterOS versions against the vendor’s fixed releases, and follow CERT’s preservation and recovery steps if compromise is suspected.
- Procurement and operations leaders: Confirm that deployed home and small‑office MikroTik devices retain default firewall rules that block public access to management ports, and require verified installation sources by directing teams to the official RouterOS downloads.
- End users and administrators of single devices: If you cannot apply the update immediately, turn off exposed services or restrict management access to trusted networks and avoid initiating TLS or use of built‑in SSH clients from unpatched devices.
The record supplied by CERT Polska and the vendor points to an active, high‑impact exploitation chain focused on internet‑exposed SSH, mandatory patches listed by MikroTik, and concrete detection and recovery steps. The Hacker News has contacted CERT Polska and MikroTik for comment; the public advisory and the vendor’s fixes are the operational anchors for any immediate response.
Original report: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html




