# Analysis identifies two flaws behind exploited MikroTik router takeover chain

_Published Wednesday, September 23, 2026 at 12:40 PM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Analysis identifies two flaws behind exploited MikroTik router takeover chain — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjudzrtqX93WzCbZQoGI06WzKFtFpQsZaQB7GUao4yzBncGN3nxn0GzmYNybpL9SeKFttznMsVCZpQEQ_fD5kP_0nJRL4ZN6ZgHrXR2c33bpZN33gEyIkk6aBtx0k7znzalUe6epmrCO5VSCCH6beY_chvz9Pl0t5BbBtCLntTnNMwi3cFPXFd0p09FxA4/s1700-nu-rw-lo-l85-e365/microtik.jpg)

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection reach the command stage early; the other lets a crafted username influence the login program's privilege settings.

Attack logs date to at least September 2, before MikroTik released fixes the next day. CERT Polska's latest analysis explains how the flaws work together and reports successful account creation on affected devices. The chain requires SSH to be reachable by the attacker, and no authoritative count of compromised devices has been published.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html)

---
Canonical: https://techandbusiness.org/newswire/1dRxLR-NjuzDUwwRzhHcFV
Published: 2026-09-23T16:40:15.699Z
Story chronology: 2026-09-23T16:06:41.000Z
Retrieved: 2026-09-23T18:30:23.058Z
Publisher: Tech & Business (techandbusiness.org)
