Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Brief
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.
- 2, 7.
- 5, or 6.
- 21 immediately and check logs.
Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active exploitation on September 5, 2026, the same day CERT Polska issued its advisory titled “ Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended .”
“If you have a MikroTik router on the internet with SSH open, it may already be compromised” Raiu wrote on Medium.
