• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-67276: authentication bypass in MikroTik RouterOS

An unauthenticated remote attacker can open an SSH command channel as any user on MikroTik RouterOS, enabling command execution on affected devices (CVE-2026-67276). The flaw exists in SSH RSA public-key matching: RouterOS compares key type and modulus but omits the exponent, allowing an attacker who knows a valid RSA modulus to present a crafted key and bypass authentication. Affected releases are 7.9 through before 7.23.4 and 7.24 through before 7.24.2; the attacker needs network access to the SSH service and knowledge of an authorized RSA modulus.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.1HIGH
EPSS
0.06451
CWE
CWE-347
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply vendor fixes immediately because public exploit code exists and the flaw allows unauthenticated SSH access to an internet-facing service. Prioritize patching devices reachable from untrusted networks.

What is CVE-2026-67276?

An unauthenticated remote attacker can open an SSH command channel as any user on MikroTik RouterOS, enabling command execution on affected devices (CVE-2026-67276). The flaw exists in SSH RSA public-key matching: RouterOS compares key type and modulus but omits the exponent, allowing an attacker who knows a valid RSA modulus to present a crafted key and bypass authentication. Affected releases are 7.9 through before 7.23.4 and 7.24 through before 7.24.2; the attacker needs network access to the SSH service and knowledge of an authorized RSA modulus. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of MikroTik RouterOS are affected?

BRANCHAFFECTEDFIXED
7.x7.24 – before 7.24.27.24.2
7.x7.9 – before 7.23.47.23.4

Is CVE-2026-67276 being exploited?

Public exploit code is available.

How to fix CVE-2026-67276

  1. Upgrade RouterOS to 7.23.4 (long-term) or 7.24.2 (stable).
  2. If you cannot upgrade immediately, block or restrict SSH access to management interfaces from untrusted networks.
  3. Rotate SSH keys for accounts that may have exposed RSA moduli and replace RSA keys with other approved algorithms where feasible.
  4. Monitor SSH logs for unexpected session opens and unusual authenticated commands; alert on new keys or unfamiliar moduli.

Frequently asked questions

Is CVE-2026-67276 being actively exploited?

Public exploit code is available for CVE-2026-67276, which increases the risk of active exploitation.

Which RouterOS versions are affected by CVE-2026-67276?

RouterOS releases 7.9 up to but not including 7.23.4, and 7.24 up to but not including 7.24.2 are affected.

Is there a patch for CVE-2026-67276?

Yes. MikroTik fixed the issue in RouterOS 7.23.4 (long-term) and 7.24.2 (stable). Upgrade to one of those versions.

Does CVE-2026-67276 require authentication?

No. The flaw allows an attacker with network access and knowledge of an authorized RSA modulus to bypass authentication and open an SSH command channel.

References