Essential Guide: Mitigating MikroTik Threats on Your Network

In case you missed it, we have +2.6 million exposed MikroTik instances. Top: Brazil, Indonesia, USA. Time to check your networks.
​
I’ve had several peers ask to dust off the MikroTik security guide from 2023. Here is an update:
​
Essential Guide: Mitigating MikroTik Threats on Your Network
​https://www.senki.org/essential-guide-mitigating-mikrotik-threats-on-your-network/​
​
Shadowserver now has a new dedicated report for MikroTik. These started reporting out (daily) MikroTik instances with exposed proprietary services, such as WinBox & Bandwidth Test server (btest): https://www.shadowserver.org/what-we-do/network-reporting/accessible-mikrotik-service-report/

Tree map stats:

https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=mikrotik&source=mikrotik6&data_set=count&scale=log&auto_update=on

MikroTik boxes should not be publicly accessible on the Internet due to potential vulnerabilities, such as the recent CVE-2026-67277 https://nvd.nist.gov/vuln/detail/cve-2026-67277

You can find all Shadowserver’s MikroTik detections in Device ID report:

https://www.shadowserver.org/what-we-do/network-reporting/device-identification-report/

(around 3M daily): https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&vendor=mikrotik&dataset=count&limit=100&group_by=geo&stacking=stacked&auto_update=on

For MikroTik with SSH enabled, check out Shadowserver’s Accessible SSH reporting (https://shadowserver.org/what-we-do/network-reporting/accessible-ssh-report/), with the tag ‘mikrotik’:

https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=ssh&source=ssh6&tag=mikrotik%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on – just over 119K seen daily currently

Background:

https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/