DIRAS TAKE
Act urgently: vendor fixes are available and the issue is listed by CISA as exploited in the wild, and public exploit code exists. Patch exposed systems or apply compensating controls immediately.
What is CVE-2026-67279?
RouterOS SSH improperly advances the connection protocol after a client-initiated rekey even when user authentication has not completed. An unauthenticated client can open a session channel and send an exec request that the server dispatches, allowing creation, overwrite, or reconstruction of files in the device's managed file namespace, including configuration and diagnostic files. The vulnerability requires network access to the RouterOS SSH service and can be triggered without valid credentials on affected builds.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Which versions of MikroTik RouterOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.24 – before 7.24.2 | 7.24.2 |
| 7.x | 7.0.0 – before 7.23.4 | 7.23.4 |
| 6.x | 6.0.0 – before 6.49.21 | 6.49.21 |
Is CVE-2026-67279 being exploited?
CISA lists this vulnerability as exploited in the wild (date added 2026-09-25). Public exploit code is also available. As of 2026-09-29 there are public reports and official tracking of in-the-wild exploitation.
How to fix CVE-2026-67279
- Upgrade to a fixed RouterOS release: 6.49.21, 7.23.4, or 7.24.2 as applicable.
- If you cannot patch immediately, restrict access to the device management interfaces (block or limit SSH from untrusted networks).
- Monitor system logs and the RouterOS file namespace for unexpected file creation or modification.
- Follow the vendor advisory and CISA guidance for applying mitigations and forensics requirements.
Frequently asked questions
Is CVE-2026-67279 being actively exploited?
Yes. CISA added this vulnerability to its KEV catalog as exploited in the wild on 2026-09-25.
Which RouterOS versions are affected?
Affected releases are 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2. Fixed releases are 6.49.21, 7.23.4, and 7.24.2.
What can an attacker do if they exploit this?
An unauthenticated attacker who reaches the SSH service can open a session channel and send exec commands that the server executes, enabling creation or modification of files within the RouterOS managed file namespace, including configuration and diagnostic files.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67279
- cve.org/CVERecord?id=CVE-2026-67279
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279
- cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited
- npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain
- mikrotik.com/supportsec/september-2026-vulnerability
- forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- All MikroTik CVEs on CVE Radar
- CVEs published in September 2026