Attackers Hijack MikroTik Routers via Internet-Exposed SSH Without Authentication

Executive Summary

CERT Polska warns that attackers exploit MikroTik routers’ internet‑exposed SSH service to gain full administrative control without authentication. The attacks began at least by September 2, with no confirmed victim count reported by Hacker News. The vulnerability allows remote takeover of the routers’ management interface.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-06T09:32:38+00:00 - Category: threat-intel

Original Description: Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

"Let us revere, let us worship, but erect and open-eyed, the highest, not the lowest; the future, not the past!"

— Charlotte Gilman
Source: The Hacker News