MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-07 · via BleepingComputer

Active exploitation of MikroTik RouterOS vulnerabilities allows full router takeover

Image via BleepingComputer
Image via BleepingComputer

Attackers are actively exploiting a chain of two critical vulnerabilities in MikroTik RouterOS to gain full administrative control over routers with exposed SSH services. The flaws, discovered by Poland's CERT, enable authentication bypass and privilege escalation, and have been dubbed "MikroTrick." MikroTik has released patches, but users are urged to apply them immediately to prevent compromise.

Expanded Detail

The exploit chain pairs an SSH authentication bypass with a privilege escalation flaw, both affecting RouterOS. A separate bandwidth-test service vulnerability can leak kernel memory or crash devices. Patches were issued across multiple RouterOS versions on September 3rd, and the updates include a startup check that flags unauthorized configuration changes.

Poland's CERT provided specific indicators, including log entries and two malicious IP addresses. ShadowServer data shows over 122,000 devices have SSH exposed. For suspected compromises, the agency advises isolating the router, performing a factory reset, and rebuilding from a trusted configuration while rotating all credentials.

Context

This exploit chain could severely impact organizations relying on MikroTik hardware for network edge security. Full router takeover may allow attackers to intercept sensitive traffic, launch internal attacks, or enlist devices into botnets. Small businesses and home users with unpatched, internet-facing SSH services are particularly at risk. The widespread exposure suggests a significant number of networks could be silently compromised, undermining trust in network infrastructure until patches are universally applied.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Emergency hotfix issued for critical N-central remote code execution bug · Cybersecurity
SonicWall SMA 1000 Flaws Under Active Exploitation; Rockwell Automation Patches Multiple Products · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers exploit new MikroTik RouterOS flaws to hijack routers.” Browse more stories.