MikroTik's Silent Patch: How a Username of '-2' Grants Full RouterOS Admin

Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain

On September 3, 2026, MikroTik silently patched a critical SSH vulnerability across all RouterOS branches, withholding details. By diffing the binaries, a researcher uncovered two flaws: a low-exponent RSA signature forgery and a legacy file-descriptor login transport. The latter allows an authenticated read-only SSH session to inject a full policy mask via a username of '-2', escalating to full command execution. The patch adds input validation, but a credential-free initial access vector remains unknown.

If you ship the fixed binaries to the entire planet, then the diff between old and new is the disclosure.

More from this day

2026-09-05