Costin Raiu

Costin Raiu

@craiu · Twitter ·

MikroTik ssh 0day in the wild with massive exploitation going on since September 2. Patches went out on Sep 3. Initially looked like a 1day but now it seems exploitation actually began one day before the patches were released. 🤯

Costin Raiu

Costin Raiu

Heads up, there is a 1-day full MikroTik RCE chain against SSH being used in the wild. Patch was released yesterday, so if you have a MikroTik router with ssh open on the internet, it may already be compromised. Detection guidance and IOCs courtesy of @CERT_Polska_en https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/