HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Attackers Hijack MikroTik Routers via Unauthenticated Internet‑Exposed SSH

CERT Polska reports that MikroTik routers with SSH exposed to the Internet can be accessed without authentication, granting attackers full admin control. This highlights the importance of continuous access‑control monitoring and configuration assurance for audit readiness.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Attackers Hijack MikroTik Routers via Unauthenticated Internet‑Exposed SSH

What Happened – CERT Polska disclosed that MikroTik routers with the SSH service exposed to the Internet can be accessed without any authentication, allowing attackers to obtain full administrative control. The issue has been observed in the wild since at least 2 September 2026.

Why It Matters for Trust & Control Assurance

  • Unauthenticated remote access violates the core access‑control objective that a continuous control‑assurance program must monitor and evidence.
  • The gap highlights the need for automated configuration‑validation and continuous monitoring of network‑device hardening.
  • Demonstrating that remote services are properly segmented and authenticated provides defensible audit evidence across multiple frameworks (e.g., NIST CSF 2.0).

Who Is Affected – Service providers, enterprises, and telco operators that deploy MikroTik routers for edge or branch networking.

Recommended Actions

  • Inventory all MikroTik devices and verify SSH is either disabled or restricted to trusted management networks.
  • Deploy configuration‑compliance tooling to continuously monitor remote‑access settings and generate audit‑ready evidence.
  • Apply any MikroTik RouterOS patches that address the SSH authentication bypass and enforce MFA for privileged access.

Technical Notes – The vulnerability is an authentication bypass in the SSH daemon of RouterOS, exploitable without credentials. No CVE identifier has been assigned yet; the issue is tracked via CERT Polska advisory. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →