Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
2026-09-07T07:23:40Z•c379454aa674ad400fa013686e1f92826335e0732d291ed9f963c22d474757bc
MikroTikSSH authentication bypassactively exploited vulnerabilityincident responsenetwork device compromisepatch managementpersistenceunauthorized accounts
What happened
SANS ISC reports that MikroTik released a patch for an actively exploited vulnerability enabling SSH authentication bypass. Attackers are adding accounts to compromised devices for persistence, so affected devices should be treated as compromised, patched immediately, and investigated for unauthorized accounts and other indicators of compromise.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c379454aa674ad400fa013686e1f92826335e0732d291ed9f963c22d474757bc
- Enrichment time
- 2026-09-07T07:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.