The Polish CERT has released an urgent security advisory for users of MikroTik's RouterOS versions 6 and 7. If you're using #MikroTik #RouterOS ,please carefully read the following advisory and immediately update your servers to the latest available version. The uncovered vulnerabilities may allow external attackers to hijack your RouterOS server and to take full administrative control of it. This may result in a) loss of confidentiality and integrity of the data you're transmitting via your server and b) in misuse of your server for illegal activities. You can find more information about the recently discovered vulnerability on the Polish CERT website: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/

The issues are resolved in the following versions:

    7.25beta3
    7.24.2
    7.23.4
    6.49.21

If you are not on one of these versions, yet, you should consider yourself vulnerable and immediately update your server. In order to verify whether your server has already been affected by the security vulnerability, you may look for a newly created user called "ops" with elevated privileges. In case you see such user, your server has already been taken over and you should update your server immediately and check for further signs of breach (other users, unknown keys, unknown configuration, etc.)