Skip to content
archiveexploit · 07 Sep 2026 · 11:39 UTC

Attackers Exploited MikroTik RouterOS Flaws a Day Before Patches Shipped

EXPLKEV3 CVEsource · THC
KEVActive exploitation (KEV)
SHODANShodan: ~197,800 MikroTik exposed worldwide (07 Sep)

CISA KEV means this flaw has been seen exploited in real attacks — not predicted, observed. Treat it as urgent regardless of its score.

What to do
  • On CISA KEV — actively exploited. Patch immediately.
  • ~197,800 MikroTik are exposed worldwide — check your own version.

last 60 dispatches · spectrum

Hücumçular internetə açıq MikroTik router-lərini 2 sentyabrda ələ keçirməyə başlayıb — bu, Latviya istehsalçısının patch buraxmasından bir gün, milli qurumların texniki detalları açıqlamasından isə üç gün əvvəl olub. CERT Polska 5 sentyabrda RouterOS-da altı zəiflik açıqlayıb, real hücumlarda istifadə olunan CVE-2026-67276 daxil iki zəiflikdən ibarət zəncirə "MikroTrick" adı verilib. Bu göstərir ki, patch hazır olana qədər zəiflik artıq exploit olunurdu. MikroTik router istifadə edən təşkilatlara RouterOS-u dərhal yeniləmək tövsiyə olunur.

CVE · detail
Sources · 2

outlets reporting the same story — pick one to read

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected