Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

2026-09-06T14:51:38Z0570ba2c4b64a47e72a85d7d3296bde895a5e760f4a734285c9f2c512023b371
CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-85046AI securityCISA KEVChromium V8MikroTik RouterOSPaperCutPostgreSQLSSHVM escapeVMware FusionVMware Workstationactive exploitationcredential theftcritical infrastructuredata breacheducation sectormalwareserver takeoverzero-day

What happened

Security Affairs feed covering active exploitation of a MikroTik RouterOS SSH zero-day, exploited PaperCut vulnerabilities in education organizations, critical VMware Workstation/Fusion VM-escape flaws, a Chromium V8 vulnerability added to CISA KEV, PostgreSQL server takeover via CVE-2026-6471, and a major Manchester Airports Group data breach. The highest-priority items are active exploitation and internet-exposed device risks requiring immediate patching and incident investigation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0570ba2c4b64a47e72a85d7d3296bde895a5e760f4a734285c9f2c512023b371
Enrichment time
2026-09-06T14:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.