If you own a MikroTik router, bad news. You router is vulnerable to getting pwned:
Critical MikroTik authentication-bypass and privilege escalation vulnerabilities allow external attackers to seize control of routers via exposed SSH ports, and active exploitation is already underway. The manufacturer chose to issue a vaguely worded security update, even as 122,500+ MikroTik routers sit with SSH exposed.
MikroTik shipped RouterOS fixes on September 3rd, 2026, with release notes that mention only an “important security update.” The company strongly recommends an update, but provides no technical details.
For the first time ever, MikroTik also sent users a push notification through its app to alert them about the update.
“To give time to update your systems, we are not currently publishing detailed information,” the security advisory reads.
Larry Pesce, VP of Services, Finite State (https://www.linkedin.com/in/larrypesce)
“The interesting thing about MikroTik isn’t the CVE chain itself, it’s what it says about where attackers keep choosing to point their effort. This is a very old argument dressed up in new CVEs. Network infrastructure was the original attack surface, back when worms and DNS cache poisoning and route hijacking were the front page news. Then defenders hardened the perimeter, and attackers moved to the endpoint: client-side exploits, macros, phishing. Then EDR got good at watching endpoints, and attackers moved again, first to cloud and identity, then to the explosion of IoT and connected devices that nobody was watching at all.
“Now the pendulum is swinging back toward infrastructure. Edge appliances, VPN gateways, and routers like these MikroTik boxes are attractive again for exactly the reason they were attractive twenty years ago: almost nothing runs an agent on them, almost nobody patches them promptly, and almost nobody actually knows how many of them they have exposed to the internet.
“That last point is the one worth sitting with. Most organizations have spent the last decade building real inventory and telemetry for laptops and servers. Very few have done the same for the network gear sitting between those systems and the internet. A router doesn’t show up in your EDR console. It usually isn’t in the CMDB unless someone remembered to put it there. It gets touched during install and then left alone until something breaks. That is precisely the blind spot this kind of campaign is built to exploit, and it’s also why 120,000 exposed devices is a plausible number rather than a shocking one. Nobody set out to leave that many boxes reachable on purpose. It’s an accumulation of the same basic inventory gap, repeated at scale.
“There’s also a targeting-philosophy shift worth naming. Compromising a router at scale isn’t usually about that one router. It’s about building a broad, disposable base, proxy points, relay infrastructure, a wide net of footholds, rather than a single surgical intrusion into one high-value target. That’s a different economic model than the supply-chain-style precision compromise we talk about more often, and it changes what ‘defense’ needs to look like.
“You’re not trying to stop one determined actor from reaching one target. You’re trying to avoid being one anonymous node in somebody’s infrastructure, which is a numbers game, and numbers games get won or lost on unglamorous things like patch cadence and knowing what you actually have exposed.
“None of this is new. It’s the same swing the industry has made every few years: infrastructure, then endpoint, then cloud, then device, and back to infrastructure again, each time landing wherever defenders most recently stopped paying attention.
“The lesson isn’t really about MikroTik. It’s that ‘know your inventory’ never stopped being step one, and the network layer is overdue for the same rigor we finally applied to endpoints.”
If you have one of these routers, update now. If you can’t update it, toss it and get a new one. Because you can bet that the bad guys are trying to pwn everything that they can.
Related
This entry was posted on September 8, 2026 at 1:30 pm and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
MikroTik routers have been pwned
If you own a MikroTik router, bad news. You router is vulnerable to getting pwned:
Critical MikroTik authentication-bypass and privilege escalation vulnerabilities allow external attackers to seize control of routers via exposed SSH ports, and active exploitation is already underway. The manufacturer chose to issue a vaguely worded security update, even as 122,500+ MikroTik routers sit with SSH exposed.
MikroTik shipped RouterOS fixes on September 3rd, 2026, with release notes that mention only an “important security update.” The company strongly recommends an update, but provides no technical details.
For the first time ever, MikroTik also sent users a push notification through its app to alert them about the update.
“To give time to update your systems, we are not currently publishing detailed information,” the security advisory reads.
Larry Pesce, VP of Services, Finite State (https://www.linkedin.com/in/larrypesce)
“The interesting thing about MikroTik isn’t the CVE chain itself, it’s what it says about where attackers keep choosing to point their effort. This is a very old argument dressed up in new CVEs. Network infrastructure was the original attack surface, back when worms and DNS cache poisoning and route hijacking were the front page news. Then defenders hardened the perimeter, and attackers moved to the endpoint: client-side exploits, macros, phishing. Then EDR got good at watching endpoints, and attackers moved again, first to cloud and identity, then to the explosion of IoT and connected devices that nobody was watching at all.
“Now the pendulum is swinging back toward infrastructure. Edge appliances, VPN gateways, and routers like these MikroTik boxes are attractive again for exactly the reason they were attractive twenty years ago: almost nothing runs an agent on them, almost nobody patches them promptly, and almost nobody actually knows how many of them they have exposed to the internet.
“That last point is the one worth sitting with. Most organizations have spent the last decade building real inventory and telemetry for laptops and servers. Very few have done the same for the network gear sitting between those systems and the internet. A router doesn’t show up in your EDR console. It usually isn’t in the CMDB unless someone remembered to put it there. It gets touched during install and then left alone until something breaks. That is precisely the blind spot this kind of campaign is built to exploit, and it’s also why 120,000 exposed devices is a plausible number rather than a shocking one. Nobody set out to leave that many boxes reachable on purpose. It’s an accumulation of the same basic inventory gap, repeated at scale.
“There’s also a targeting-philosophy shift worth naming. Compromising a router at scale isn’t usually about that one router. It’s about building a broad, disposable base, proxy points, relay infrastructure, a wide net of footholds, rather than a single surgical intrusion into one high-value target. That’s a different economic model than the supply-chain-style precision compromise we talk about more often, and it changes what ‘defense’ needs to look like.
“You’re not trying to stop one determined actor from reaching one target. You’re trying to avoid being one anonymous node in somebody’s infrastructure, which is a numbers game, and numbers games get won or lost on unglamorous things like patch cadence and knowing what you actually have exposed.
“None of this is new. It’s the same swing the industry has made every few years: infrastructure, then endpoint, then cloud, then device, and back to infrastructure again, each time landing wherever defenders most recently stopped paying attention.
“The lesson isn’t really about MikroTik. It’s that ‘know your inventory’ never stopped being step one, and the network layer is overdue for the same rigor we finally applied to endpoints.”
If you have one of these routers, update now. If you can’t update it, toss it and get a new one. Because you can bet that the bad guys are trying to pwn everything that they can.
Share this:
Like this:
Related
This entry was posted on September 8, 2026 at 1:30 pm and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.