Over 31M MikroTik Devices Indexed Online Amid Active RouterOS Exploit Chain
CERT Polska disclosed a two-CVE exploit chain called MikroTrick on September 5, 2026, targeting MikroTik RouterOS devices with SSH management ports exposed to the internet. The chain combines a missing authentication flaw in SSH public-key verification with an argument injection vulnerability, requiring no password or private key to gain administrator access. ZoomEye data collected on September 19, 2026 shows over 31 million MikroTik-fingerprinted records indexed, though these figures reflect scan observations and do not confirm vulnerable or compromised devices. Public reporting cites more than 122,000 potentially exposed instances, a figure distinct from confirmed intrusions. MikroTik has released patched versions including 6.49.21, 7.23.4, 7.24.2, and 7.25beta3, and administrators are urged to audit SSH reachability across their networks and update immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in