Vulnerabilities
Attackers take over MikroTik routers through flaws that already have a patch
Two RouterOS flaws let attackers into a MikroTik router's administration without a password, according to CERT Polska, and CISA considers them exploited. The patch has been available since 3 September. If your office uses a MikroTik, check its version and whether it can be managed from the internet.
MikroTik — Vendor of the affected product (RouterOS)

In 30 seconds
- According to CERT Polska, combining two RouterOS flaws gives full access to a MikroTik router's administrative console without a password, if its SSH service is reachable.
- The first recorded attacks date from 2 September, one day before MikroTik released the fix: RouterOS 7.24.2, 7.23.4 and 6.49.21.
- On 25 September CISA added CVE-2026-67279, one of the two flaws, to its catalogue of actively exploited vulnerabilities.
- MikroTik recommends updating, not opening management ports to the internet and checking whether the device shows signs of intrusion.
Does this affect me?
It affects you if your company uses a MikroTik router (running RouterOS) that hasn't been updated since 3 September, especially if someone can manage it over SSH from the internet. The router is usually chosen and installed by the provider, so you may have one without knowing it. No Spanish victims have been confirmed.
What happened
On 3 September 2026, MikroTik released what it described as "an important security update" for RouterOS, the operating system of its routers. In its advisory it explained that it was holding back the details: "To give time to update your systems, we are not currently publishing detailed information."
On 22 September, Poland's national incident response team, CERT Polska, published its analysis. According to CERT Polska, combining two flaws, a chain it has named MikroTrick, "resulted in full unauthenticated access to the administrative console" of the router through its SSH service. The earliest public attack logs date from 2 September, before the patch existed.
On 25 September, the US cybersecurity agency (CISA) added CVE-2026-67279, one of those flaws, to its catalogue of actively exploited vulnerabilities.
What we know
- Fixed versions (according to MikroTik): RouterOS 7.24.2, 7.23.4 and 6.49.21, plus the 7.25beta3 test release. Earlier versions are affected.
- Condition for the attack: the router's SSH service has to be reachable by the attacker. MikroTik points out that its default configuration blocks that access from the internet; the risk appears when someone has opened it.
- What attackers do: CERT Polska describes the creation of new administrator accounts and the sending of the router's diagnostic files to external servers.
- Exposure: according to Shadowserver data cited by BleepingComputer, on 5 September there were 122,500 MikroTik devices with SSH reachable from the internet. It isn't known how many of them were vulnerable.
- CERT Polska explains that it used AI agents to speed up the technical analysis of the flaws.
What we don't know yet
- How many routers have been compromised. There is no public figure.
- Whether there are victims in Spain. None have been confirmed.
- The exact identifiers. MikroTik's advisory cites CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277; CERT Polska and CISA attribute the chain to CVE-2026-86060 and CVE-2026-67279, and CERT Polska says some publications wrongly associated CVE-2026-67276 with MikroTrick. For your company nothing changes: the fixed versions are the same.
Why it matters
The router is the device all of the office's traffic passes through. Whoever controls it can see or redirect that traffic and use it as a way into the network, without needing to trick anyone with an email.
And a pattern repeats itself: the attackers started before the patch, and the real risk lies in the devices that are still not updated weeks later.
What it means for an SME
In a small company, the router is usually chosen and installed by the telecom operator or the IT provider. That has two common consequences:
- the company doesn't know which brand of router it has or who updates it;
- to be able to provide remote support, the installer sometimes leaves the administration open to the internet, exactly the condition this attack needs.
What your company should do this week
- Ask your IT provider or your telecom operator whether there is a MikroTik router in your office and which version of RouterOS it runs. If it's earlier than 7.24.2, 7.23.4 or 6.49.21, ask them to update it.
- Ask for the router's administration not to be open to the internet. MikroTik recommends limiting SSH to trusted networks and, for remote support, using a VPN instead of opening ports.
- Ask them to check for signs of intrusion: users or scripts nobody recognises and the "Flagged" device warning that MikroTik describes. Updating closes the door, but it doesn't remove anyone who already got in.
- Put in writing who maintains the router and how often it is updated.
If you don't know which of your company's devices can be managed from the internet, a cybersecurity audit starts exactly there.
Sources
- MikroTik — «September 2026 vulnerability» (3 September 2026)Primary source
- CERT Polska — «MikroTrick: technical analysis, disclosure process, and the use of LLM agents» (22 September 2026)Primary source
- CISA — «CISA Adds Two Known Exploited Vulnerabilities to Catalog» (25 September 2026)Primary source
- BleepingComputer — «Hackers exploit new MikroTik RouterOS flaws to hijack routers» (7 September 2026)
Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.


