Skip to main content
Security

MikroTik patches RouterOS flaws linked to device takeovers

MikroTik patches RouterOS flaws linked to device takeovers Image: Primary
MikroTik has released RouterOS updates for six vulnerabilities after CERT Poland said attackers were chaining two of them to take full control of devices with SSH exposed to public networks. The two flaws, called MikroTrick, include an authentication bypass and a session privilege-manipulation issue, each rated 9.2 CVSS. CERT Poland said exploitation has occurred since at least September 2. Shadowserver found more than 120,000 MikroTik devices with internet-accessible SSH during a September 5 scan window.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Security
Security

CISA adds exploited Chromium V8 flaw to KEV catalog

CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...

Security
Security

Natural Resources Wales discloses employee diversity-data exposure

Natural Resources Wales disclosed that a spreadsheet containing equality-monitoring and diversity information for former and current employees was inadvertently published online and later removed. The affected group covers people...