Assume Your MikroTik Is Compromised (09/06/2026)

September 6, 2026
Assume Your MikroTik Is Compromised (09/06/2026)
Key Intel / TL;DR
  • MikroTik patched an already-exploited SSH authentication bypass, and the guidance from analysts is to assume compromise rather than to check.
  • CERT Polska warned that attackers are reaching internet-exposed MikroTik SSH to gain full administrative control without authenticating.
  • Sansec disclosed an unpatched Magento Open Source and Adobe Commerce zero-day allowing unauthenticated code execution on store servers.
  • Elastic Security Labs documented four REVSTEALER-linked modules that persist after the stealer deletes itself, one of them disabling Windows Update.

Three stories on a Sunday, and the MikroTik one carries an instruction most advisories avoid. Analysts are not telling you to check whether you were hit, they are telling you to assume you were and to work backward from there. That distinction changes the whole response, because verification and remediation are different budgets and only one of them starts today.

Top 3 Critical Security Alerts

1. MikroTik SSH Bypass Is Exploited, and the Advice Is to Assume Compromise

MikroTik patched an already-exploited vulnerability allowing an SSH authentication bypass, and attackers have been adding new accounts to affected devices. CERT Polska warned separately that attackers are reaching MikroTik routers whose SSH service is exposed to the internet and taking full administrative control without authenticating at all. The account-creation detail is what makes patching insufficient, because a device that was compromised before the fix keeps the attacker’s account through the upgrade. SANS Internet Storm Center has the patch guidance and The Hacker News covers the CERT Polska warning.

Operator Note: Patch, then enumerate every account and SSH key on the device and delete what you cannot account for, because the upgrade preserves the attacker’s access and the dashboard will show you a patched router.

2. An Unpatched Magento Zero-Day Is Backdooring Stores

Dutch e-commerce security company Sansec published an advisory on a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets attackers run code on a store’s server without logging in. Unpatched means there is no update to apply, so the available controls are a web application firewall rule, restricting administrative paths, and watching for new files in the webroot. An online store server holds the payment integration and the customer database, which is why this class of flaw gets weaponized within hours. The Hacker News has the Sansec advisory.

3. REVSTEALER Leaves Four Modules Behind After It Deletes Itself

Elastic Security Labs documented four previously unreported programs tied to REVSTEALER, an emerging Windows information stealer, that stay on an infected machine after the stealer removes itself, with one of them switching off Windows Update to keep the host from repairing itself and another running a crypto miner. Self-deletion is designed to defeat exactly the investigation most teams run, which is to find the malware. The stealer being gone is the expected outcome and it tells you nothing about whether the machine is clean. The Hacker News has the module analysis.

Operator Note: A host that stopped receiving Windows updates for no stated reason is an incident indicator, so check update compliance drift against your endpoint inventory rather than treating it as a patching backlog.


The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)