Critical MikroTik Vulnerability – Patch Now
Executive Summary
Mikrotik issued a patch for a known vulnerability that permits SSH authentication bypass. The flaw is actively exploited; attackers add new accounts to compromised devices to maintain persistence after patching. Users should apply the update immediately and verify device integrity.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-09-06T21:43:17+00:00 - Category: threat-intel
Original Description: Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
"In separateness lies the world's great misery, in compassion lies the world's true strength."
— Buddha