Hackers have begun exploiting a pair of newly disclosed vulnerabilities in MikroTik RouterOS to gain control of routers with SSH services exposed to the internet. The attacks leverage a chain of two flaws to bypass authentication and execute arbitrary code on affected devices.
What happened
Security researchers observed active exploitation targeting MikroTik routers running RouterOS. The attack chain combines two vulnerabilities to achieve remote code execution. Devices with SSH services accessible from the internet are at risk, though the exact number of exposed systems remains unclear. MikroTik has not yet released patches for these flaws, leaving operators reliant on mitigations such as disabling SSH access or restricting it to trusted IP ranges.
The vulnerabilities were disclosed in early September 2026, with proof-of-concept exploits circulating shortly after. While the source did not specify the date of disclosure, exploitation activity was detected within days of public awareness. No details about the attackers' identity or motives have been confirmed, nor has the scale of compromised devices been quantified.
What we don't know yet
The total number of vulnerable or compromised routers is unknown. Researchers have not identified the threat actors behind the attacks, and MikroTik has not provided a timeline for patch availability. The potential impact on downstream services—such as DNS resolution, VPN connectivity, or network traffic routing—remains unassessed. Operators are advised to monitor MikroTik's official channels for updates and apply mitigations immediately.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 7 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No existing article covers this MikroTik RouterOS flaw exploitation.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers MikroTik RouterOS vulnerabilities.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=516 slug=mikrotik-routeros-flaws-exploited-in-active-attacks quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: Source does not specify the exact disclosure date of the vulnerabilities, only that they were disclosed 'in early September 2026'. The draft states this correctly but could clarify that the date is inferred from the source's publication date and relative timing.
- Style compliance: The draft uses 'early September 2026' as a specific timeframe, which is not explicitly stated in the source. While reasonable, this phrasing could be softened to 'recently disclosed' to avoid implying precision not present in the source.
- Quote integrity: No blockquotes are used in the draft, complying with the style guide. However, the draft does not include a verbatim quote from the source, which could have strengthened the piece if available.
- Audience relevance and notability: The story is highly relevant to hosting, DNS, and network professionals, as MikroTik routers are widely used in these industries. The lack of a patch and active exploitation make this actionable and notable.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #25: None of the provided candidates match the article topic about MikroTik RouterOS vulnerabilities. The only candidate (index 0) describes a Pexels photo of a government cloud data center in Belgium, which is unrelated to MikroTik routers, vulnerabilities, or security exploits. The alt text and URL slug do not align with the article's focus on RouterOS flaws or active attacks.
- Assigning hero image — Reused library image reused image #283
- Linking related stories — Linked 5 relations from 447 candidates
- Linking related stories — Linked 5 relations from 448 candidates
- Publishing — Published mikrotik-routeros-flaws-exploited-in-active-attacks
- Mastodon — Posted https://mstdn.social/@hostingpaper/117229674929058338




Discussion · coming soon
Be the first to join the thread when community discussion launches.