Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
2026-09-06T14:51:38Z•0570ba2c4b64a47e72a85d7d3296bde895a5e760f4a734285c9f2c512023b371
CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-85046AI securityCISA KEVChromium V8MikroTik RouterOSPaperCutPostgreSQLSSHVM escapeVMware FusionVMware Workstationactive exploitationcredential theftcritical infrastructuredata breacheducation sectormalwareserver takeoverzero-day
What happened
Security Affairs feed covering active exploitation of a MikroTik RouterOS SSH zero-day, exploited PaperCut vulnerabilities in education organizations, critical VMware Workstation/Fusion VM-escape flaws, a Chromium V8 vulnerability added to CISA KEV, PostgreSQL server takeover via CVE-2026-6471, and a major Manchester Airports Group data breach. The highest-priority items are active exploitation and internet-exposed device risks requiring immediate patching and incident investigation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 0570ba2c4b64a47e72a85d7d3296bde895a5e760f4a734285c9f2c512023b371
- Enrichment time
- 2026-09-06T14:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.