Malwarebytes reports that attackers are exploiting flaws in some MikroTik routers running vulnerable RouterOS versions with SSH remote access exposed online. Owners should update RouterOS and close public management access.
In 60 seconds
- MikroTik owners should care if their router runs vulnerable RouterOS and allows SSH access from the internet.
- Check the router model, RouterOS version, and whether internet users can reach its management services.
- Install the supported RouterOS update through MikroTik’s official update path and close public SSH access.
- Do not rely on a strong password alone or clear a Flagged status without reviewing the configuration.
Who should check a MikroTik router
This matters to anyone using a MikroTik router with a vulnerable RouterOS version, especially when SSH remote management is accessible from the internet. RouterOS is the software that runs the router. The risk can affect home networks and organizations that use MikroTik equipment.
Start by confirming whether the network uses a MikroTik router. The device label, its management page, purchase records, or the person who manages the network can help. Check the installed RouterOS version and whether SSH can be reached from the internet. SSH, or Secure Shell, is a tool for making an encrypted remote connection to a device.
If you do not manage the network, ask the responsible network administrator or service provider to perform these checks. Avoid changing settings on a business or shared network unless you are authorized to do so.
What the reported flaws can allow
Malwarebytes reports that CERT Polska warned of active exploitation involving a chain of critical MikroTik RouterOS flaws. The described risk applies when a router has a vulnerable RouterOS version and its SSH service is accessible from the internet.
Two flaws in the reported chain can work together. One can bypass RSA public-key authentication, a login method based on a matched pair of digital keys. The other can help an attacker gain administrator rights. In plain terms, an attacker may be able to get in without a password and then take control of the router.
A compromised router sits between the internet and the devices on a network. Malwarebytes says an intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, change firewall rules, or use the router to reach other devices. DNS helps turn website names into the network addresses computers use.
What to do today
Install the supported RouterOS security update as soon as possible. Malwarebytes says owners can use the router’s update feature or get the supported package directly from MikroTik. The update option should be available under “Check for updates.” Use MikroTik’s official update path, not a download site or an unexpected message link.
Close public access to the router’s management services, especially SSH, if remote administration is not required. If remote access is necessary, limit it to known internet addresses rather than allowing connections from anywhere.
Malwarebytes reports that MikroTik added a startup check for selected signs of unauthorized configuration changes. When the check finds recognized suspicious entries, RouterOS disables those entries and sets the device’s Flagged status to Yes. Administrators can check the status with `/system/device-mode/print`. A flagged device still needs a full configuration review before anyone clears the status.
Why the router’s position matters
A router controls how many people and devices reach the internet. If an attacker takes it over, changing one setting could affect every device behind it. The result could include visits to the wrong websites, altered network protections, or a path into other systems.
The report does not say that every MikroTik router has been compromised. It does say attackers are exploiting the described flaws. The practical response is to identify the device, check its RouterOS version and SSH exposure, apply the official update, and review unusual configuration changes.
Does this affect me?
- Who may be affected
- People and organizations using MikroTik routers with a vulnerable RouterOS version, particularly when SSH remote management is accessible from the internet.
- How to check
- Confirm the device is a MikroTik router, check its RouterOS version, and ask the network administrator whether SSH or other management services can be reached from the internet.
- What to do
- Install the supported RouterOS security update through MikroTik’s update feature or an official supported package, then close public SSH access unless it is required.
- What to avoid
- Do not rely on a strong password alone, use unofficial update downloads, or clear a Flagged status before reviewing the router’s full configuration.
Common questions
How can I tell whether my MikroTik router is affected?
Confirm that the device is a MikroTik router, check its RouterOS version, and determine whether SSH management is reachable from the internet. The report does not list every affected version, so use MikroTik’s official update path or ask the person who manages the network to check the device against supported packages.
Is changing the router password enough?
No. One reported flaw can bypass RSA public-key authentication, so a strong password does not by itself stop the attack. Update RouterOS and remove public SSH access. If remote administration is needed, limit it to known internet addresses.
What does a Flagged status mean?
Malwarebytes says RouterOS can mark a device as Flagged when its startup check finds selected signs of unauthorized configuration changes. The system may disable recognized suspicious entries, but the full configuration still needs review before the status is cleared.
What if I do not manage the router myself?
Contact the person or company responsible for the network. Ask them to check the MikroTik model, RouterOS version, SSH exposure, update status, and any Flagged status. Do not change settings on a shared network without authorization.
Primary source
This article is based on Malwarebytes, “MikroTik router flaws allow takeover without a password,” published September 8, 2026: https://www.malwarebytes.com/blog/news/2026/09/mikrotik-routers-can-be-taken-over-without-password. Malwarebytes attributes the warning to CERT Polska. Read the complete original source.
Concerned this may affect your computer or account?
Bring the exact alert, device, product, and timeline. Leon will help separate urgent action from noise.
Article history: Published Sep 8, 2026 at 6:52 am EDT. Updates and corrections are noted here when material facts change.
