Since I've not heard or seen this before today.... (albeit a week late even) Cert Poland released this "Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended " But we all secure ssh anyway... right.... https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-active... https://mikrotik.com/supportsec/september-2026-vulnerability/ -- _Regards,_ _Noel Butler_
When you install the recent update that Mikrotik sent a notification about, it'll flag if some of the common compromise indicators are there ssh <hostname> /system/device-mode/print | grep flagged flagged: no Depends on how you define "secure ssh" - the vague mentions around the place seem to indicate it was an auth bypass of some sort - so "key auth only" would potentially leave you open. On 2026-09-09 16:01 Noel Butler via Public wrote:
Since I've not heard or seen this before today.... (albeit a week late even)
Cert Poland released this "Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended "
But we all secure ssh anyway... right....
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-active...
https://mikrotik.com/supportsec/september-2026-vulnerability/
-- _Regards,_ _Noel Butler_ _______________________________________________ Public mailing list -- public@talk.mikrotik.com.au To unsubscribe send an email to public-leave@talk.mikrotik.com.au
participants (2)
-
James Hodgkinson -
Noel Butler