Hackers exploit new MikroTik RouterOS flaws to hijack routers
Two vulnerabilities chained to bypass authentication and gain remote root access

Key Takeaways
- A chain of two RouterOS vulnerabilities is being actively exploited to hijack devices with SSH exposed to the internet.
- The flaws enable unauthenticated remote code execution and privilege escalation to root.
- MikroTik has not released official patches; mitigation involves restricting SSH access and network segmentation.
- No confirmed CVEs or CVSS scores are publicly assigned at the time of this report.
- Users are advised to monitor for anomalous activity and apply defensive measures immediately.
Quick answers
- What happened?
- Security researchers have identified a chain of two vulnerabilities in MikroTik RouterOS that allows threat actors to hijack devices with SSH services exposed to the internet. The flaws enable unauthenticated remote code execution and privilege escalation, leading to full device compromise.
- Which products are affected?
- RouterOS
- What should defenders do?
- Restrict SSH access to trusted networks only, disable SSH if not required, monitor logs for anomalous authentication attempts, and apply any firmware updates released by MikroTik when available. Network segmentation is recommended to limit lateral movement.
Recent reporting indicates that threat actors are exploiting a chain of two recently disclosed vulnerabilities in MikroTik RouterOS to gain unauthorized control of routers. Devices with SSH services exposed to the internet are particularly at risk. The exploitation chain leverages the vulnerabilities to bypass authentication mechanisms and escalate privileges, ultimately allowing remote code execution with root-level access. MikroTik has not yet released official patches, and users are advised to restrict SSH access and monitor for anomalous activity. The vulnerabilities affect RouterOS versions in deployment globally, with the exact scope under investigation. No official CVE assignments have been confirmed at the time of reporting, but the issues are being tracked by security communities. The emergence of active exploitation underscores the need for timely mitigation and network segmentation for affected infrastructure.
Security Details
Two vulnerabilities in MikroTik RouterOS are being chained together to achieve unauthenticated remote code execution and privilege escalation. The exact technical vectors are under analysis, but the chain allows threat actors to bypass authentication and gain root-level control of affected devices. SSH services exposed to the internet are the primary attack vector.
Affected products
RouterOS
Mitigation
Restrict SSH access to trusted networks only, disable SSH if not required, monitor logs for anomalous authentication attempts, and apply any firmware updates released by MikroTik when available. Network segmentation is recommended to limit lateral movement.
Sources
BleepingComputer
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Sep 7, 2026 · 10:32
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.


