Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

2026-09-07T07:23:40Zc379454aa674ad400fa013686e1f92826335e0732d291ed9f963c22d474757bc
MikroTikSSH authentication bypassactively exploited vulnerabilityincident responsenetwork device compromisepatch managementpersistenceunauthorized accounts

What happened

SANS ISC reports that MikroTik released a patch for an actively exploited vulnerability enabling SSH authentication bypass. Attackers are adding accounts to compromised devices for persistence, so affected devices should be treated as compromised, patched immediately, and investigated for unauthorized accounts and other indicators of compromise.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c379454aa674ad400fa013686e1f92826335e0732d291ed9f963c22d474757bc
Enrichment time
2026-09-07T07:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.