decrypted · 8 september 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law

MikroTik routers are being hijacked exactly as NCSC warned they would be

This week's most instructive vulnerability did not come out of nowhere. On 27 August the NCSC told UK organisations to get remote management interfaces off the public internet and onto a segregated network. Six days later, attackers were doing precisely what that advisory warned about, working their way into MikroTik routers over an exposed SSH port. Poland's national CSIRT, CERT Polska, disclosed the underlying flaws on 5 September and counted 122,500 vulnerable devices already reachable from the internet.

The trick in "MikroTrick"

The attack chain, which researchers nicknamed MikroTrick, combines two bugs. CVE-2026-67276 (CVSS 9.2) is an SSH authentication bypass: RouterOS is supposed to verify a client's full cryptographic key during login, but the flawed code only compares the public modulus, one number derived from the key, without confirming the rest matches. It is the equivalent of a bouncer checking the first few digits of an ID card and waving through anyone who gets those right. Paired with CVE-2026-86060, a privilege escalation bug triggered by a maliciously crafted username, an attacker with no credentials at all can end up with full administrative control. CERT Polska says the exploitation has been running since at least 2 September, with attackers creating hidden privileged accounts with names such as "ops" and "-2".

Why this matters beyond the spec sheet

MikroTik's RouterOS is cheap, capable and everywhere: wireless ISPs, hotels, small business networks and temporary site connectivity all lean on it. None of that is unique to the UK, but the exposure is the same one the NCSC named weeks earlier: administrative access sitting on the public internet instead of behind a management network that attackers cannot reach at all. A patch is not a substitute for that architecture, it is a second line of defence for when the first one has already failed. MikroTik has shipped fixes in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21. Where patching cannot happen immediately, CERT Polska's advice is to disable SSH, web and bandwidth-test access from the internet entirely. Either way, the lesson predates this specific bug: if a device's management port is reachable from anywhere on earth, a vulnerability in it is only a matter of time.

Also this week

A written assurance is not a control. Crypto wallet maker Trezor's breach, first disclosed on 13 August as affecting roughly 14,000 customers, has grown to 81,000 after Trezor discovered that its shipping partner ShipMonk had kept years of order data, names, emails, phone numbers and addresses, that it had repeatedly confirmed in writing it had deleted. The data dated back to 2019. For any UK organisation that outsources customer data to a fulfilment or logistics provider, the lesson is blunt: a contractual deletion clause is worthless without an audit to check it actually happened.

Parliament widens who counts as critical. The Cyber Security and Resilience Bill entered Committee stage in the House of Lords on 1 September, and its scope expansion is the headline: managed service providers and data centre operators become regulated entities for the first time, pulling roughly 1,000 more organisations into statutory cyber requirements, alongside a new power to designate critical suppliers based on how much their customers depend on them. Royal Assent is not expected until late 2026 and enforcement not until around 2028, but UK MSPs and data centre operators watching this land would do well to start now rather than wait for the secondary legislation.

Sources

Questions about any of this, or want to talk through what it means for your own systems? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.