:

MIKROTIK ROUTER FLAWS EXPLOITED IN ACTIVE HIJACKING ATTACKS

SECURITY DESK1 MIN READ
MON, SEP 7, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Hackers are actively exploiting a chain of two newly disclosed vulnerabilities in MikroTik RouterOS to seize control of routers with exposed SSH services. The attacks target internet-facing devices and pose immediate risk to affected networks.

■ Attack Details Security researchers have documented active exploitation of two linked vulnerabilities in MikroTik RouterOS. The flaws enable attackers to gain unauthorized access to routers when Secure Shell (SSH) services are accessible from the internet. The vulnerability chain works by chaining multiple weaknesses together, allowing attackers to escalate privileges and achieve full device control. Once compromised, routers become entry points for broader network intrusions. ■ Affected Systems MikroTik RouterOS devices with SSH exposed to the internet are at highest risk. Organizations running public-facing routers without proper access restrictions are primary targets. ■ Mitigation Steps MikroTik has released patches addressing the disclosed flaws. Organizations should: - Update RouterOS to the latest patched version immediately - Restrict SSH access to trusted IP addresses only - Disable SSH if remote management is not required - Use VPN or bastion hosts for administrative access - Monitor router logs for suspicious connection attempts ■ Industry Impact MikroTik routers are widely deployed in small business networks, ISPs, and service provider environments. The active exploitation of these vulnerabilities increases urgency for network administrators to apply fixes. Previous MikroTik vulnerabilities have been weaponized by threat actors within days of disclosure. Security teams should prioritize patching as an immediate action item.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researchers discovered that LG smart TVs continue recording audio and scanning local networks even when the display is powered down. The findings raise concerns about user privacy and device security.

2H AGOIndustry Desk

ConnectWise has disclosed a new vulnerability in ScreenConnect remote access software without an immediate patch available. The company is offering temporary mitigation measures while preparing a fix for later this week.

2H AGOIndustry Desk

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.

5H AGOIndustry Desk

QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.

19H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.