ZeroHour
SANS Internet Storm Centerpublished ()ingested

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

criticalExploit / PoC exploited in the wildimportance 82
AI summary · glm-5.3-flash

MikroTik patched a critical SSH authentication bypass already exploited in the wild; attackers add accounts to affected routers for post-patch persistence.

MikroTik released a patch late last week for a critical vulnerability allowing SSH authentication bypass that is already being exploited in the wild, per the vendor's September 2026 advisory. Attackers have been adding new accounts to affected devices to maintain access even after the patch is installed. The patch attempts to detect compromise and set a 'Flagged' status on affected devices, and SANS ISC advises administrators to assume compromise.

  • Exploited flaw allows SSH authentication bypass on MikroTik devices.
  • Attackers create new accounts for persistence that survives patching.
  • September 2026 patch attempts compromise detection and sets a 'Flagged' status.
  • SANS ISC urges administrators to assume compromise and review affected devices.
VendorsMikroTik
ProductsRouterOS
Full article84 words · extracted from isc.sans.edu · click to collapse

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

The patch will attempt to detect compromise and set the "Flagged" status.

Details:

https://mikrotik.com/supportsec/september-2026-vulnerability

--

Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter |

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Text extracted automatically; images, tables and formatting may be missing. Original: https://isc.sans.edu/diary/rss/33314