CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5748

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers are exploiting MikroTik routers with internet-exposed Secure Shell (SSH) services to achieve unauthenticated administrative access, according to CERT Polska. Active exploitation began by at least September 2, 2026.

Why it matters: Organizations running MikroTik routers with SSH exposed to the internet risk immediate compromise and full device takeover; audit network perimeter access and disable SSH exposure or enforce authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary