September 8, 2026
- MikroTik hunting guidance is now concrete. CERT Polska points to unexpected highly privileged ops accounts and account-creation log entries containing
ssh:-2@ as investigation triggers, plus RouterOS Flagged status via /system/device-mode/print — preserve evidence before clearing Flagged. Fixed builds are 6.49.21, 7.23.4 (use 7.23.5 on long-term, which corrects an IPv6 DHCP regression), and 7.24.2. Attacks date to at least 2 September with patches on the 3rd, which The Hacker News notes does not by itself establish zero-day status (The Hacker News, earlier coverage).
· Vulnerabilities & Exploits
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 7, 2026
- MikroTik's three same-day RouterOS builds (7.23.4 long-term, 7.24.2 stable, 6.49.21) shipped with a deliberately vague "important security update" banner — and one changelog line present in all three branches, absent from 7.23.3: "ssh - refactor SSH internal processes". Diffing the NPK packages, npratley.net documents three bugs and two chains: a low-exponent RSA signature forgery reaching an overflow in
mtget with confirmed controlled code execution, and — matched to an active-exploitation support trace — an SSH username of -2 reaching a legacy file-descriptor login transport, letting a read-only session supply its own policy mask and escalate to the full RouterOS policy set, producing exactly the campaign-shaped ops account defenders have been finding. The author is explicit about the boundary he did not cross: he has not reproduced a stock, credential-free way to make SSH accept literal user -2. The work was AI-driven and took roughly six hours. A MikroTrick PoC is public, tracked as CVE-2026-67276. CERT Polska's warning went out 5 September with attacks dating to at least 2 September and no victim count; CERT-LV described mass attacks (@campuscodi); SANS ISC says assume compromise, because attackers are adding accounts that survive the patch (earlier coverage).
· Exploitation & Active Attacks
in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
September 6, 2026
- Attackers are taking over MikroTik RouterOS devices whose SSH service is exposed to the internet. CERT Polska disclosed six flaws—CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060—including two critical issues. Its active-exploitation alert calls for immediate updates and compromise checks; the technical advisory covers the full set.
· Vulnerabilities & Exploits
in One Loophole, 100 Agents, 27 Minutes