Hey WondTech readers! We've got an important security alert for you today, concerning thousands of MikroTik routers. Experts have discovered that roughly 9,560 MikroTik RouterOS devices worldwide are still openly responding to SSH connection requests directly from the internet, putting them at serious risk.

What does this mean for you? If you own a MikroTik router for your home or business, or if you manage a network that uses these devices, you need to pay close attention. This exposure of the SSH service to the internet is exactly the condition that attackers need to exploit these devices. There are critical vulnerabilities (like CVE-2026-67277 and CVE-2026-86060), disclosed by CERT Polska in September 2026, that allow unauthorized attackers to gain full administrative control over your device once exploited. The Cybersecurity and Infrastructure Security Agency (CISA) has even added these two vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting their severity and the urgent need to address them.

Research shows that while there are about 8.09 million devices running MikroTik's RouterOS generally visible on the internet, the more concerning figure is the 9,560 devices that specifically expose their SSH service. This number isn't just a statistic; it represents a real, exploitable weakness. It's important to remember that this figure is considered a 'floor,' meaning the actual number of exposed devices could potentially be higher. Typically, SSH, which is used for remote device management, should not be exposed to the public internet unless absolutely necessary, and even then, with stringent security measures in place.

So, if you're using a MikroTik device, we strongly advise you to check your settings. Make sure that the SSH service isn't unnecessarily open to the internet from the outside. If you don't use it, disable it. If you do need it, restrict access to specific IP addresses only and use very strong, unique passwords. Most importantly, always ensure your router's firmware is updated to the latest versions to patch any known security flaws. Protecting your network starts with your router.