Jessica Entwistle
September 7 2026
Attackers are actively exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to reporting from The Register and SANS Internet Storm Center. CERT Polska published an attack warning on 5 September, confirming that successful attacks have been observed since at least 2 September. MikroTik released a patch late last week, but organisations should assume compromise if devices were exposed before patching. Attackers have been creating new administrative accounts on affected devices to maintain access even after patches are applied.
MikroTik routers are widely deployed in UK businesses, particularly in smaller organisations, managed service environments and branch office connectivity. SSH services exposed to the internet create an attack surface that bypasses perimeter defences entirely. Once an attacker has administrative access to a router, they control routing, DNS, firewall rules and VPN configurations, which can enable lateral movement, traffic interception, credential harvesting and persistent access across the wider network. The fact that attackers are pre-emptively creating backdoor accounts suggests they expect widespread patching and are planning for long-term access. This is not a vulnerability that can be addressed through patching alone; it requires a full review of device configuration, account auditing and potentially a rebuild if compromise is suspected.
Immediately review whether MikroTik routers or other network devices have SSH or management interfaces exposed to the internet. Apply the latest firmware from MikroTik, audit all administrative accounts for unexpected additions, and verify that remote management is restricted to VPN access or trusted IP ranges only. If devices were exposed to the internet before patching, treat them as potentially compromised and consider a full rebuild with credential rotation across connected systems. Ensure that network device management is part of your regular vulnerability and configuration review process, with clear ownership and escalation paths in place.
Source: The Register