|
In case you missed it, we have +2.6 million exposed MikroTik instances. Top: Brazil, Indonesia, USA. Time to check your networks. Tree map stats: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=mikrotik&source=mikrotik6&data_set=count&scale=log&auto_update=on MikroTik boxes should not be publicly accessible on the Internet due to potential vulnerabilities, such as the recent CVE-2026-67277 https://nvd.nist.gov/vuln/detail/cve-2026-67277 You can find all Shadowserver’s MikroTik detections in Device ID report: https://www.shadowserver.org/what-we-do/network-reporting/device-identification-report/ (around 3M daily): https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&vendor=mikrotik&dataset=count&limit=100&group_by=geo&stacking=stacked&auto_update=on For MikroTik with SSH enabled, check out Shadowserver’s Accessible SSH reporting (https://shadowserver.org/what-we-do/network-reporting/accessible-ssh-report/), with the tag ‘mikrotik’: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=ssh&source=ssh6&tag=mikrotik%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on – just over 119K seen daily currently Background: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ |
Essential Guide: Mitigating MikroTik Threats on Your Network
