Attackers are actively taking over internet-exposed MikroTik routers without passwords
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 9th, 2026.
Organizations can lose control of their network edge because attackers are actively chaining MikroTik RouterOS weaknesses against internet-exposed S S H services. One weakness allows an attacker to gain access without a valid password. A second weakness can elevate that access to administrator level. Once attackers control a router, they may be able to change D N S settings, intercept or redirect traffic, manipulate firewall rules, create remote-access tunnels, or move toward other systems on the network. Patched RouterOS releases are available.
A strong password can’t protect a device when the authentication process itself can be bypassed. Any management service exposed to the public internet makes this issue more urgent. Leaders should confirm that network teams have a current inventory of routers that allow remote administration. Defenders should update RouterOS, close public S S H access, restrict necessary administration through a V P N or allowlist, and fully audit any device marked as flagged. Network-edge management should be private by default. Patch RouterOS now, remove public S S H access, and audit every exposed router for unauthorized changes.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.news.