BriefPulse Security · Security reporting tied to advisories, affected versions and action. RSS · BriefPulse network
BriefPulse Security

Exposures, incidents and defensive changes for people who have to act.

16 September 2026

Brief

MikroTik SSH authentication bypass exploited; patch released

MikroTik released a patch late last week for an SSH authentication bypass that is already being exploited. SANS ISC advises affected organizations to assume compromise.

MikroTik released a patch late last week for an SSH authentication bypass that is already being exploited, SANS ISC reports. The diary's guidance is blunt: at this point, assume compromise.

Attackers have been adding new accounts to affected devices so they keep access even after the patch is installed, which means patching alone may not evict an intruder.

For small teams running MikroTik gear, the protective step is to apply the patch and then review affected devices for accounts that should not be there.

Our reading

Our view is that small teams on affected MikroTik devices should patch and then hunt for unauthorized accounts, because the diary says to assume compromise.

What to do or watch

Assume compromise: apply the MikroTik patch, then review affected devices for accounts that should not be there, because attackers have been adding accounts to maintain access after patching. Watch whether unauthorized accounts remain on the device even after the patch is installed.

Source details and supporting facts

Each line is stated by the page named above it.

Stated by SANS Internet Storm Center

  • MikroTik released a patch late last week for an already-exploited vulnerability.
  • The vulnerability allows an SSH authentication bypass.
  • The vulnerability is already being exploited.
  • Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
  • SANS ISC advises that affected organizations assume compromise.

Sources

  1. SANS Internet Storm CenterText stored 14 September 2026

How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.

What that means
  • 5 of 5 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
  • Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
  • The check reads stored text only: no claim rests on a fresh look that did not happen.
  • Where the reporting was silent, the text says so instead of filling the gap.

More from Security