About the author
Chris Harrison
Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.
MikroTik routers are everywhere in rural Kansas. They run farm and ranch networks, small-town businesses, churches and many local wireless internet providers. They are affordable and powerful, and right now attackers are actively breaking into them.
In September 2026, security researchers and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed attacks against MikroTik’s RouterOS. Attack logs go back to early September. By chaining two flaws, an attacker can skip the router’s SSH login entirely and gain full administrator control. CISA has added the flaws to its list of vulnerabilities known to be exploited.
The attack needs one thing: the router’s SSH service reachable from the internet. If SSH can’t be reached from outside, this chain can’t start.
Update RouterOS to one of these releases or newer:
Don’t stop at the main router. Check every MikroTik device: wireless bridges, tower radios, switches and the spare in the closet.
As one research team put it, being patched and being clean are two separate questions. Investigators found compromised routers with a hidden script that recreated a backdoor administrator account every day, even after the password was changed. If your router was exposed before you updated, assume it may have been visited.
If you find any of these, a password change is not enough. The router should be completely reset and reinstalled, then set up again from scratch, and every password or key it stored should be changed.
Running MikroTik and not sure what version you are on, or whether SSH is open? Call us at 620-960-8711. We can check and secure your routers on-site or remotely. See our business networking and Wi-Fi services.
Sources: ReCa Tools: The MikroTik router takeover, corrected · CISA KEV alert, Sept. 25, 2026
Want more free guides like this? Browse our Scam & Security Library — real examples of phishing emails, scam texts, fake pop-ups and more.
Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.
Call the local guys. We’re happy to help — no pressure.