Ness City Computer Service LLC

Home › Blog › Networking
Networking

MikroTik Router Owners: Attackers Are Taking Over Routers. Patching Alone Isn’t Enough

By Chris Harrison · October 8, 2026 · 5 min read

MikroTik routers are everywhere in rural Kansas. They run farm and ranch networks, small-town businesses, churches and many local wireless internet providers. They are affordable and powerful, and right now attackers are actively breaking into them.

What happened

In September 2026, security researchers and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed attacks against MikroTik’s RouterOS. Attack logs go back to early September. By chaining two flaws, an attacker can skip the router’s SSH login entirely and gain full administrator control. CISA has added the flaws to its list of vulnerabilities known to be exploited.

The attack needs one thing: the router’s SSH service reachable from the internet. If SSH can’t be reached from outside, this chain can’t start.

Fixed versions

Update RouterOS to one of these releases or newer:

  • 7.24.2 (stable)
  • 7.23.4 (long-term)
  • 6.49.21 (for older v6 devices)

Don’t stop at the main router. Check every MikroTik device: wireless bridges, tower radios, switches and the spare in the closet.

Why updating isn’t the end of it

As one research team put it, being patched and being clean are two separate questions. Investigators found compromised routers with a hidden script that recreated a backdoor administrator account every day, even after the password was changed. If your router was exposed before you updated, assume it may have been visited.

Check for these signs

  • User accounts you don’t recognize, especially one named “ops” with full rights
  • Scripts or scheduled tasks you didn’t create
  • Changed DNS, NAT, firewall or VPN settings
  • Diagnostic or backup files being created or sent out

If you find any of these, a password change is not enough. The router should be completely reset and reinstalled, then set up again from scratch, and every password or key it stored should be changed.

Lock it down going forward

  1. Turn off SSH, WinBox, WebFig and API access from the internet, or limit them to specific trusted addresses.
  2. Manage routers through a VPN instead of open ports.
  3. Use strong, unique admin passwords and remove default or unused accounts.
  4. Keep RouterOS on a regular update schedule.

Running MikroTik and not sure what version you are on, or whether SSH is open? Call us at 620-960-8711. We can check and secure your routers on-site or remotely. See our business networking and Wi-Fi services.

Sources: ReCa Tools: The MikroTik router takeover, corrected · CISA KEV alert, Sept. 25, 2026

Want more free guides like this? Browse our Scam & Security Library — real examples of phishing emails, scam texts, fake pop-ups and more.

Chris Harrison, owner of Ness City Computer Service
About the author
Chris Harrison

Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.

Have a question about your tech?

Call the local guys. We’re happy to help — no pressure.

Services

How we can help

Computer repair & PC sales

Managed IT services

Cybersecurity

Networking & Wi-Fi

Backup & disaster recovery

VoIP business phones

Surveillance & alarms

Web design & hosting

Scroll to Top