HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical MikroTik RouterOS SSH Authentication Bypass Exploited – Immediate Patch Required

MikroTik RouterOS contains a critical SSH authentication bypass that is already being exploited. Attackers add persistent accounts to compromised devices, underscoring the need for robust authentication controls and rapid patch management for audit readiness.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 isc.sans.edu
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
isc.sans.edu

Critical MikroTik RouterOS SSH Authentication Bypass Exploited – Immediate Patch Required

What Happened — MikroTik released a critical patch for a RouterOS flaw that permits SSH authentication bypass. The vulnerability is already being weaponised in the wild, and attackers have been creating persistent accounts on compromised devices even after the patch is applied.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of gaps in authentication and account‑management controls – a core control objective that continuous‑monitoring programs must evidence.
  • Highlights the need for real‑time vulnerability management and proof that patches are applied before exploitation.
  • Shows why audit‑ready logging of privileged‑account changes is essential to prove due diligence during assessments.

Who Is Affected – Service providers, enterprises, and telecom operators that deploy MikroTik routers for edge or WAN connectivity.

Recommended Actions

  • Deploy the MikroTik RouterOS patch immediately on all affected devices.
  • Conduct an inventory sweep for any unauthorized accounts created post‑exploit and remove them.
  • Enable multi‑factor authentication for SSH access where possible and enforce strong password policies.
  • Integrate the vulnerability into your continuous patch‑management workflow and capture remediation evidence for audit readiness.

Technical Notes – The flaw bypasses SSH authentication, allowing attackers to log in without valid credentials. Exploitation is confirmed in the wild; attackers add new privileged accounts to retain access after patching. Source: SANS Internet Storm Center

📰 Original Source
https://isc.sans.edu/diary/rss/33314

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →