<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers exploit new MikroTik RouterOS flaws to hijack routers]]></title><description><![CDATA[<p dir="auto">Attackers are actively chaining two recently disclosed security flaws in MikroTik RouterOS to seize control of devices that have SSH services exposed online. The campaign targets routers that have not yet been updated with the vendor’s latest patches.</p>
<p dir="auto">The exploitation chain combines a privilege escalation vulnerability with an authentication bypass issue. When used together, they allow an unauthenticated remote attacker to gain administrative access to the router. Once inside, the attackers can modify device settings, inject malicious configurations, or use the compromised router as a pivot point for further network intrusions.</p>
<p dir="auto">The flaws affect RouterOS versions that predate the latest stable release. MikroTik has already addressed the issues in newer firmware builds, and administrators are strongly advised to apply those updates without delay. In addition to patching, it is recommended to restrict SSH access to trusted IP addresses only, and to disable the service entirely if it is not strictly required.</p>
<ul>
<li>Affected: MikroTik RouterOS versions prior to the latest patched release.</li>
<li>Mitigation: Update to the latest RouterOS build, enforce firewall rules to limit SSH exposure, and audit device logs for unusual activity.</li>
</ul>
<p dir="auto">Routers are often overlooked in patch management routines, yet they remain a high-value target for attackers seeking persistent access to internal networks. Given that this exploitation is already underway, immediate action is warranted.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Is your organisation currently exposing SSH on any MikroTik devices, and if so, how are you prioritising the rollout of these critical updates?</p>
]]></description><link>https://xploitlk.com/topic/253/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:12:02 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/253.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2026 20:30:22 GMT</pubDate><ttl>60</ttl></channel></rss>