13 min read
MikroTikRouterOS+6 more
MikroTrick: The MikroTik RouterOS SSH Bypass That Was Being Exploited Before the Patch Even Shipped
Two chained RouterOS bugs let an attacker log into a MikroTik router as an existing user without their private key, then escalate straight to root. CERT Polska confirmed exploitation a day before patches existed, and 122,500+ internet-facing routers are still exposed.
Sep 15, 20260