Sławomir Rozbicki and CERT Polska identify critical MikroTik RouterOS vulnerabilities being actively exploited by external attackers
CERT Polska identified six vulnerabilities in MikroTik RouterOS software, including two critical flaws that allow unauthenticated attackers to seize full control of a device via exposed SSH ports. The administration announced that these issues were fixed in RouterOS versions 6.49.21, 7.23.4, and 7.24.2. Security researchers discovered that combining two specific vulnerabilities—an SSH authentication bypass and a privilege escalation flaw—allows an attacker to take full control of a device without authentication. This exploit chain, dubbed "MikroTrick," has been actively exploited since at least September 2, 2026, before patches were released. CERT Polska confirmed successful attacks originating from IP addresses 82.192.72.4 and 103.102.31.18. These attacks are characterized by a login failure for the username "-2" and the creation of an "ops" account. MikroTik issued a push notification to alert users, recommending that owners of devices with exposed SSH ports update to the patched versions immediately. Users are advised to check the "Log" section for a "Flagged" status to determine if their devices were already compromised before the update.
Sources
-
Vulnerabilities in Mikrotik RouterOS software
cert.pl
-
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Security Affairs
-
MikroTik RouterOS flaws put exposed routers at risk
Cybernews