As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS
MikroTik released patches for three vulnerabilities in RouterOS: improper RSA key exponent verification enabling SSH signature forgery, username handling flaws allowing privilege escalation in SSH login, and unauthenticated IPv4 UDP test initiation causing kernel restarts. CERT Poland reports active exploitation targeting routers with public SSH exposure, combining multiple vulnerabilities to gain full device control.
Why it matters: Network administrators running MikroTik RouterOS with exposed SSH services face immediate risk of unauthorized access and device compromise; apply patches promptly and restrict SSH via virtual private network (VPN) or IP whitelist.
- Source published
- First seen by Cybersecurity Tracker