# Attackers Hijack MikroTik Routers via Open SSH, CERT Polska Warns Users to Patch Now

*Sunday, September 6, 2026 at 10:05 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-06T10:05:46.381Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/17049.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are hijacking MikroTik routers through internet‑exposed SSH services with no authentication, prompting CERT Polska to urge RouterOS users to update immediately and check for unknown accounts and scripts.

A critical weakness in widely used MikroTik routers is allowing attackers to hijack devices through internet‑exposed SSH services without any authentication, prompting urgent guidance from CERT Polska and raising concerns over the security of home and business networks.

The issue, detailed on 6 September, affects certain versions of RouterOS, the operating system that powers MikroTik hardware. Attackers are reportedly scanning the internet for routers with remote‑management access exposed and then gaining entry without a password. Once inside, they can create new administrative users, add scripts and maintain persistent control over the device.

For end users, compromised routers may appear to function normally while being used to intercept or redirect traffic or to participate in broader malicious campaigns. Small businesses, local providers and households that rely on MikroTik equipment are all exposed if they have not secured or updated their devices.

Operationally, the flaw gives attackers a foothold at the edge of networks, a valuable position for both financially motivated groups and more sophisticated operators. From there, they can map internal systems, attempt to move deeper into networks or use the router as a relay to hide the origin of other attacks.

CERT Polska has advised administrators to update RouterOS as soon as possible to versions that address the issue, and to then manually inspect devices for unfamiliar user accounts, scheduled tasks and scripts that could indicate an earlier compromise. This reflects the risk that patching alone does not remove attackers who have already established access.

The case comes alongside other reports of persistent malware families that can steal digital wallets, hijack clipboard data, act as proxies and mine cryptocurrency, sometimes by weakening built‑in security tools after gaining higher privileges. Together, these developments show how attackers are focusing on quietly seizing control of infrastructure components.

For regulators and large service providers, the incidents highlight how consumer‑grade networking gear, when widely deployed, can create systemic vulnerabilities. Efforts to encourage or require more secure defaults, better update mechanisms and clearer support lifecycles are likely to gain urgency as such issues emerge.

Key signals to watch include how quickly MikroTik users apply available updates, whether large internet providers begin scanning and assisting customers with vulnerable devices, and whether upcoming cyber incidents trace their infrastructure back to hijacked routers of this type. These factors will determine whether the problem remains contained or develops into a broader network‑level threat.
