DIRAS TAKE
Urgent: apply vendor fixes immediately because public exploit code exists and the flaw allows unauthenticated SSH access to an internet-facing service. Prioritize patching devices reachable from untrusted networks.
What is CVE-2026-67276?
An unauthenticated remote attacker can open an SSH command channel as any user on MikroTik RouterOS, enabling command execution on affected devices (CVE-2026-67276). The flaw exists in SSH RSA public-key matching: RouterOS compares key type and modulus but omits the exponent, allowing an attacker who knows a valid RSA modulus to present a crafted key and bypass authentication. Affected releases are 7.9 through before 7.23.4 and 7.24 through before 7.24.2; the attacker needs network access to the SSH service and knowledge of an authorized RSA modulus. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of MikroTik RouterOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.24 – before 7.24.2 | 7.24.2 |
| 7.x | 7.9 – before 7.23.4 | 7.23.4 |
Is CVE-2026-67276 being exploited?
Public exploit code is available.
How to fix CVE-2026-67276
- Upgrade RouterOS to 7.23.4 (long-term) or 7.24.2 (stable).
- If you cannot upgrade immediately, block or restrict SSH access to management interfaces from untrusted networks.
- Rotate SSH keys for accounts that may have exposed RSA moduli and replace RSA keys with other approved algorithms where feasible.
- Monitor SSH logs for unexpected session opens and unusual authenticated commands; alert on new keys or unfamiliar moduli.
Frequently asked questions
Is CVE-2026-67276 being actively exploited?
Public exploit code is available for CVE-2026-67276, which increases the risk of active exploitation.
Which RouterOS versions are affected by CVE-2026-67276?
RouterOS releases 7.9 up to but not including 7.23.4, and 7.24 up to but not including 7.24.2 are affected.
Is there a patch for CVE-2026-67276?
Yes. MikroTik fixed the issue in RouterOS 7.23.4 (long-term) and 7.24.2 (stable). Upgrade to one of those versions.
Does CVE-2026-67276 require authentication?
No. The flaw allows an attacker with network access and knowledge of an authorized RSA modulus to bypass authentication and open an SSH command channel.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67276
- cve.org/CVERecord?id=CVE-2026-67276
- cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited
- npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain
- mikrotik.com/supportsec/september-2026-vulnerability
- forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- All MikroTik CVEs on CVE Radar
- CVEs published in September 2026