Skip to content
TrustList
News

Poland orders its national cybersecurity entities to update MikroTik RouterOS now, as attackers exploit the flaws

Editorial

By TrustList Editorial

Poland’s Government Plenipotentiary for Cybersecurity recommended on 2 October 2026 that entities in the national cybersecurity system update MikroTik RouterOS without delay (7.24.2, 7.23.4, 6.49.21), check for compromise and close management services.

About Poland orders its national cybersecurity entities to update MikroTik RouterOS now, as attackers exploit the flaws

Poland orders its national cybersecurity entities to update MikroTik RouterOS now, as attackers exploit the flaws

2 October 2026 — Poland's Government Plenipotentiary for Cybersecurity issued a formal recommendation on 2 October 2026 to entities in the country's national cybersecurity system, the operators of essential and important services under Polish law, to update MikroTik RouterOS "without delay" because the flaws are being exploited. The recommendation was prepared with Poland's three national CSIRTs: CSIRT NASK, CSIRT GOV and CSIRT MON, which assessed a risk of critical incidents if it is not followed.

Not yet independently verified. The recommendation names fixed versions but no CVE numbers, so which flaws it covers is our reading: the versions match MikroTik’s own September notice for flaws CERT Polska reported as exploited, and we wrote about another RouterOS flaw, CVE-2026-84411, on 1 October. We will update this when it can be confirmed, and remove this note.

What it requires

  • Update RouterOS to at least the fixed release of your branch: 7.25 beta 3, 7.24.2, 7.23.4 or 6.49.21. These are the releases MikroTik's September vulnerability notice lists as fixed.
  • Check whether devices were compromised, following MikroTik's instructions. MikroTik's notice says devices may show a "Flagged" status in the system log if compromised.
  • Disable or block access from untrusted networks to SSH, the web interface (WWW and WWW-SSL), WinBox and the bandwidth-test server.

The recommendation says non-compliance has a negative impact on public safety and vital state security interests.

Why it matters beyond Poland

The fixed versions and the advice apply to every MikroTik device, wherever it is. CERT Polska reported in early September that the flaws were being exploited; a government now issuing a formal order a month later suggests many devices are still unpatched. MikroTik routers are common in branch offices, at internet providers and in industrial sites, and are often managed by a third party that customers never check.

What to do

  • Inventory every MikroTik device, including those your internet or managed-network provider installed, and confirm the RouterOS version.
  • Update to the fixed release of your branch, or later; our 1 October item covers a separate flaw fixed in 7.24.
  • Check the system log for a "Flagged" status and for unknown users, scripts and scheduled tasks.
  • Close SSH, web, WinBox and bandwidth-test access from the internet; manage devices over a VPN.
  • In Poland, entities in the national cybersecurity system should record what they did, as the recommendation is formal.

Sources

Categories & features