A critical router exploit zero-day is actively targeting MikroTik and ASUS devices, giving attackers full network access without authentication. Small business owners must update firmware immediately and audit internet-exposed SSH access to prevent breach.
September 6th, 2026 brings urgent security warnings for small business owners. MikroTik routers with internet-exposed SSH are being actively exploited through a zero-day vulnerability allowing full administrative takeover without authentication. Businesses must immediately update to versions 7.24.2, 7.23.5, or 6.49.21. ASUS Control Center Enterprise faces a maximum-severity flaw (CVSS 10.0) enabling remote attackers to gain complete control without passwords. E-commerce platforms running Magento or Adobe Commerce face active exploitation of the StyleSmuggler zero-day with no patch currently available. Phishing attacks have evolved to use invisible Unicode characters that bypass email security filters, requiring enhanced staff training. A cautionary tale from Winona County demonstrates that paying ransoms provides no protection - they paid $128,000 in January only to face another attack months later, reinforcing that prevention investments outweigh ransom payments.
How do you protect against active router exploit attacks?
Immediate steps: (1) Identify all MikroTik and ASUS devices connected to your network using your asset inventory or network scan tools. (2) Update firmware to patched versions today, not next week. (3) Change all default router passwords and disable SSH access from the internet. (4) Enable logging and review access logs for signs of unauthorized logins. MikroTik routers exposed to the internet are being scanned hourly by automated attack tools. CISA has published detection guidance for compromised devices. E-commerce platforms using Magento or Adobe Commerce also face active StyleSmuggler zero-day exploitation with no patch available yet. Contact your software vendors for temporary mitigations. Phishing attacks are now using invisible Unicode characters to bypass email filters, so reinforce staff training on verifying sender addresses even when message text looks legitimate.
Key takeaways
- MikroTik and ASUS routers with exposed SSH are being actively compromised right now. Update firmware to the latest patched versions (MikroTik 7.24.2 or later) today.
- Disable internet access to router SSH ports and restrict admin access to internal IP ranges only. Change all default passwords immediately.
- Magento and Adobe Commerce stores are actively targeted by StyleSmuggler zero-day with no patch. Contact vendors for interim security measures while waiting for updates.
- Phishing now uses hidden Unicode characters to bypass email filters. Train staff to verify sender addresses and hover over links before clicking, regardless of message appearance.
Frequently asked questions
How do I know if my MikroTik router is vulnerable?
Log into your router's administration interface and check System > About > Firmware. If the version is older than 7.24.2 (or 7.23.5 or 6.49.21 for legacy devices), your router is vulnerable. Also check if SSH port 22 is accessible from the internet. If yes, attackers can exploit the zero-day right now.
Can I check if my router has already been compromised?
Review your router's system log for unexpected SSH logins, especially from unfamiliar IP addresses. Look for entries labeled 'SSH user login' or 'login attempt' from outside your normal network range. If you find suspicious activity, update firmware first, change all passwords, and audit firewall rules for unauthorized changes.
Do I need to pay for firmware updates?
No. MikroTik, ASUS, and Magento updates are free. Download directly from vendor websites and avoid email links claiming to offer patches. Verify URLs match the official domain before entering credentials.
Should we pay a ransom if we get hit despite these steps?
No. Winona County paid $128,000 and was attacked again within months. Focus resources on recovery (restoring from clean backups), incident response (notifying customers and regulators), and prevention (redundant backups, network segmentation). Ransom payments fund attackers and do not guarantee data return or prevention of re-attack.
What if we use cloud-hosted routers instead of on-premise equipment?
You still need to patch and monitor. Cloud-hosted devices can be exploited just like physical routers. Verify your hosting provider's firmware version matches the patched releases and request confirmation in writing that patches have been applied before the deadline.
Sources
- https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html
- https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
- https://cybersecuritynews.com/asus-control-center-vulnerability/
- https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/
- https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
- https://www.mprnews.org/story/2026/09/06/winona-county-attacked-again-in-cyberattack-after-paying-128-ransom