DIRAS TAKE
Urgent: no authentication is required to exploit this verification bypass, so prioritize updates; MikroTik published fixes in 7.23.6 and 7.24.3. If you cannot patch immediately, restrict exposure of affected devices and monitor connections for suspicious TLS/SSH activity.
What is CVE-2026-67278?
An unauthenticated remote attacker can trick MikroTik RouterOS into accepting forged RSA/PKCS#1 v1.5 signatures and thereby impersonate TLS servers or undermine RSA-based SSH host-key checks. This is tracked as CVE-2026-67278. The flaw affects RouterOS 7.x releases 7.0.0 through before 7.23.6 and 7.24 up to before 7.24.3; an attacker needs the ability to control or redirect RouterOS outbound TLS connections or otherwise present malformed RSA signatures to the device. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of MikroTik RouterOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.24 – before 7.24.3 | 7.24.3 |
| 7.x | 7.0.0 – before 7.23.6 | 7.23.6 |
Is CVE-2026-67278 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-67278
- Upgrade affected RouterOS installations to 7.23.6 (long-term) or 7.24.3 (stable).
- If you cannot update immediately, block or restrict outbound TLS connections from RouterOS devices to untrusted destinations.
- Monitor RouterOS logs and network TLS/SSH connections for unexpected certificates or host-key changes.
- Follow vendor guidance for configuration hardening and review trust stores for untrusted roots.
Frequently asked questions
Is CVE-2026-67278 being actively exploited?
There are no public reports of active exploitation of CVE-2026-67278 as of 2026-09-30.
Which RouterOS versions are affected by CVE-2026-67278?
RouterOS 7.x releases from 7.0.0 up to before 7.23.6 and versions 7.24 up to before 7.24.3 are affected.
Is there a patch for CVE-2026-67278?
Yes. MikroTik provided fixes in RouterOS 7.23.6 (long-term) and 7.24.3 (stable).
Does CVE-2026-67278 require authentication?
No. Exploitation does not require authentication against the RouterOS device; an attacker needs the ability to control or redirect outbound TLS connections or present malformed RSA signatures.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67278
- cve.org/CVERecord?id=CVE-2026-67278
- cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited
- npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain
- mikrotik.com/supportsec/september-2026-vulnerability
- forum.mikrotik.com/t/7-23-6-long-term-is-released/273139
- forum.mikrotik.com/t/7-24-3-stable-is-released/273138
- All MikroTik CVEs on CVE Radar
- CVEs published in September 2026