Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

2026-09-06T20:51:39Z95fbb558228b0319d6fc0fa04d2d8443b9bfaefd40395020cd91f3c185459ea5
CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-85046AI abuseCISA KEVChromiumMikroTikMikroTrickPaperCutPostgreSQLRouterOSSSHV8VM escapeVMware FusionVMware Workstationactive exploitationcredential theftcritical infrastructuredata breacheducation sectorserver takeoverzero-day

What happened

Security Affairs RSS items report active exploitation and disclosure of multiple high-impact vulnerabilities and incidents, including a MikroTik RouterOS SSH zero-day campaign, exploited PaperCut flaws (CVE-2026-81578 and CVE-2026-82078), critical VMware Workstation/Fusion VM-escape vulnerabilities, a Chromium V8 flaw added to CISA KEV (CVE-2026-85046), and a PostgreSQL server-takeover vulnerability (CVE-2026-6471). Additional items cover an alleged Manchester Airports Group data breach affecting 8.8 million people and abuse of AI agents against a German wiki.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
95fbb558228b0319d6fc0fa04d2d8443b9bfaefd40395020cd91f3c185459ea5
Enrichment time
2026-09-06T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.