← All Advisories

CVE-2026-67276

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-67276

Key Details

CVECVE-2026-67276
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsMikroTik RouterOS
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MikroTikRouterOS
SubsystemsIndustrial Network - Routers/Firewalls
SectorsMulti-sector

What to Know

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

What to Do

Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67276
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-67276
Vendor advisoryhttps://mikrotik.com/supportsec/september-2026-vulnerability/