MikroTik Called It a Quiet Patch. CERT Polska Calls It “MikroTrick” — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed
🚨 CRITICAL VULNERABILITY ALERT — Network Edge / Remote Access Infrastructure: MikroTik shipped a silent, no-detail patch for RouterOS on September 3, 2026, hoping to buy administrators time before attackers reverse-engineered the flaw. CERT Polska has now confirmed the exploited chain — nicknamed MikroTrick — was already running in the wild since September 2, a full day before the patch existed…
