Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes. A vulnerable MikroTik router with SSH reachable from the internet can be taken over without authentication by chaining two RouterOS flaws confirmed in active attacks in September 2026. An attacker with administrative control can add users, scripts, scheduled tasks, proxy settings, tunnels, or other configuration that preserves access. Update to a fixed RouterOS release, restrict management services to trusted networks, and treat suspicious configuration or logs as a possible compromise—not merely a patching issue.

What the September 2026 MikroTik vulnerabilities do

CERT Polska reported active attacks against RouterOS devices whose SSH services were reachable from public networks. The attack chain combines two vulnerabilities to bypass SSH authentication and obtain full administrative privileges. CERT Polska said the released patches prevented the observed attacks.

Vulnerability What it does Severity reported by CERT Polska
CVE-2026-67276 SSH public-key authentication bypass caused by incomplete RSA-key comparison. CVSS 9.2
CVE-2026-86060 A crafted-username privilege-manipulation flaw that can yield full administrative privileges when chained with CVE-2026-67276. CVSS 9.2
CVE-2026-67277 A separate bandwidth-test service flaw that can disclose kernel memory or cause remote denial of service; it is not one of the SSH takeover pair. CVSS 8.8

CERT Polska’s 5 September 2026 advisory describes the chain this way: “Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol.” This makes exposure important: the reported attacks required SSH access from an untrusted network, rather than merely owning a MikroTik router.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which RouterOS versions contain the fixes?

CERT Polska’s advisory and MikroTik’s September 2026 bulletin list these fixed releases. The applicable version depends on the RouterOS branch installed on your device.

#1 Best Overall
Mikrotik hEX RB750Gr3 5-port Ethernet Gigabit Router
  • hEX also known as RB750Gr3 is a five port Gigabit Ethernet router for locations where wireless connectivity is not required
  • The device has a full size USB port. This new updated revision of the hEX brings several improvements in performance
  • It is affordable, small and easy to use, but at the same time comes with a very powerful dual core 880MHz CPU and 256MB RAM
  • IPsec hardware encryption (~470 Mbps) and The Dude server package is supported, microSD slot on it provides improved r/w speed for file storage and Dude
  • Dimensions: 113x89x28mm; Storage size: 16 MB; Passive PoE (PoE in); PCB temperature monitor, Voltage monitor and Mode button
Fixed release listed How to use this information
7.25 beta 3 A listed fixed release in the 7.25 beta line. Because it is a beta release, check MikroTik’s current release guidance for the appropriate production upgrade for your device.
7.24.2 Fixed release listed for the 7.24 line.
7.23.4 Fixed release listed for the 7.23 line.
6.49.21 Fixed release listed for the 6.49 line.

Upgrade immediately to the applicable fixed release or a later release that includes the fixes. Do not assume that a version number from a different branch is interchangeable; use the branch that matches your installation and MikroTik’s guidance. Patching closes the known vulnerability, but it does not remove configuration an attacker may already have added.

How attackers can leave backdoor-style access

On RouterOS, persistence can be created through configuration rather than a separate conventional malware file. An attacker with administrative control may add or alter accounts and settings so access remains after the initial exploit is no longer available.

  • Users: Look for accounts you do not recognize, especially a highly privileged account named ops, which CERT Polska observed in the attacks.
  • Scripts and scheduler tasks: Check for unfamiliar scripts or scheduled actions that could make changes or maintain access.
  • Proxy and tunnel settings: Look for unexpected proxy or SOCKS configuration, tunnels, or other unexplained network paths.
  • Logs: CERT Polska reported sequences such as login failure for user -2 from <ip> via ssh followed by user <name> added by ssh:-2@<ip>. Unfamiliar entries of this kind warrant investigation.
  • Service changes: Review whether management or network services were enabled or changed without authorization.

RouterOS has a Flagged mechanism that scans for selected unauthorized changes at startup, disables recognized suspicious entries, writes a critical log message, and sets a warning. A Flagged warning is an investigation trigger. Its absence does not prove that the router is clean: the mechanism only identifies selected changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if your MikroTik router may be exposed or compromised

  1. Record the version and preserve evidence. If compromise is suspected, note the RouterOS version and secure relevant logs and configuration before making destructive changes. Preserve copies somewhere separate from the potentially affected router.
  2. Limit access now. Block management services from untrusted networks while you investigate. Restrict SSH, Winbox, WebFig, WWW/WWW-SSL, and bandwidth-test to trusted management networks. MikroTik says, “Make sure SSH is not open to any untrusted networks,” and recommends a strong VPN such as WireGuard for remote access.
  3. Install the applicable fix. Upgrade to the fixed release for your RouterOS branch, or a later release that includes the fixes. A patch is essential even if you have not found suspicious activity.
  4. Review accounts, configuration, and logs. Check for Flagged status, unknown users, scripts, scheduler tasks, proxy servers, tunnels, unexplained service changes, and the suspicious SSH log pattern described above. Compare configuration against a trusted record if one is available.
  5. If indicators exist, isolate and rebuild. Disconnect or otherwise isolate the router from untrusted networks, preserve evidence, then factory-reset it and reconfigure it from a trusted configuration. Do not blindly restore a backup made from the suspect device: it may carry the unwanted settings back.
  6. Rotate credentials and secrets. After rebuilding, change passwords and replace affected keys and other secrets. Also change credentials that were stored on, or used to administer, the potentially compromised router.

These response choices have different consequences. Temporarily blocking public management access limits exposure while preserving the device for investigation; a factory reset is more disruptive but is the recommended route when compromise indicators are present. Saving logs and configuration before a reset helps retain evidence, while rebuilding from a trusted configuration improves recovery confidence.

How to reduce the risk of another takeover

MikroTik’s hardening guidance focuses on reducing exposed services and strengthening administration:

  • Keep RouterOS updated and use a supported, fixed release appropriate for the device’s branch.
  • Do not expose SSH or other management services to untrusted networks. Use WireGuard for remote administration rather than opening management ports publicly.
  • Change the default admin username and use a strong, unique password.
  • Retain the preconfigured firewall rules that block unsolicited WAN access, and verify that management services are limited to trusted addresses.
  • Disable MAC-Telnet, MAC-WinBox, MAC-Ping, and the bandwidth server in production if they are not needed.
  • Disable unnecessary proxy, SOCKS, UPnP, and cloud services.
  • Enable stronger SSH cryptography and review users and configuration changes periodically.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Earlier Winbox flaws show why updates and access limits both matter

The September 2026 incident involves SSH, but MikroTik management interfaces have had separate vulnerabilities. These historical cases are not the same exploit chain and do not replace the need to apply the current fixes.

Rank #4
Sale
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
  • MikroTik RouterBOARD C52iG-5HaxD2HaxD-TC-US (US Version) hAP ax (WiFi6) Quad-Core IPQ-6010 864 MHz, RAM 1GB, RouterOS, License level 4 It's time to supercharge your home network with the Generation
  • hAP ax has everything you might need in a primary home access point - and more
  • Forget endless reviews and comparisons - this is the perfect device for 99% of homes
  • Wireless signal is now stronger than ever
  • Here are the two main ingredients of hAP ax's success: a state-of-the-art dual-band, dual-chain 4-4
Issue Impact and affected versions Vendor guidance
CVE-2018-14847 MikroTik’s 2018 advisory said a Winbox vulnerability allowed a special tool to request the system user database. Affected bugfix versions were 6.30.1–6.40.7, fixed in 6.40.8; current versions 6.29–6.42, fixed in 6.42.1; and RC versions 6.29rc1–6.43rc3, fixed in 6.43rc4. Upgrade, change passwords, firewall Winbox, and inspect exported configuration for unknown SOCKS proxy settings and scripts.
CVE-2024-54772 WinBox response-size differences could allow username enumeration. Versions before 6.49.18 and 7.18 were affected. Upgrade and restrict Winbox to trusted addresses.

These examples illustrate two distinct safeguards: install fixes for the vulnerability affecting your version, and keep administration interfaces reachable only from networks that need them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 4
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
hAP ax has everything you might need in a primary home access point - and more; Forget endless reviews and comparisons - this is the perfect device for 99% of homes
$90.75
Bestseller No. 5
MikroTik L009UiGS-RM
MikroTik L009UiGS-RM
W128339515
$106.91
Best Value

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.