MikroTik released an emergency patch for a critical SSH authentication bypass vulnerability that is already being actively exploited in the wild. The vulnerability allows attackers to bypass SSH authentication on affected MikroTik devices. Exploitation has been confirmed, and attackers are creating new user accounts on compromised devices to maintain persistent access even after patching. Administrators are strongly urged to patch immediately and assume compromise if running vulnerable versions. Post-patch forensic review is recommended to identify unauthorized accounts added by attackers.