Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

2026-09-07T02:51:38Z8483754728fde14ed32137652f3efc7b7cb79341f4b3f0cbd4d0330bea190460
CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-85046CISA KEVChromium V8MikroTik RouterOSMikroTrickPaperCutPostgreSQLSSHVM escapeVMware FusionVMware Workstationactive exploitationcritical infrastructuredata breacheducation sectorserver takeover

What happened

Security Affairs RSS collection reports active exploitation of a MikroTik RouterOS SSH zero-day, exploitation of PaperCut vulnerabilities in education organizations, critical VMware Workstation/Fusion VM-escape flaws, a Chromium V8 vulnerability added to CISA's KEV catalog, a large Manchester Airports Group data breach, and a longstanding PostgreSQL code-execution flaw. The highest-priority items are the actively exploited internet-facing device and application vulnerabilities, particularly MikroTik SSH exposure, PaperCut, and Chromium.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8483754728fde14ed32137652f3efc7b7cb79341f4b3f0cbd4d0330bea190460
Enrichment time
2026-09-07T02:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.