Improper Verification of Cryptographic Signature in MikroTik RouterOS - CVE-2026-67276

 

Improper Verification of Cryptographic Signature in MikroTik RouterOS - CVE-2026-67276

Published: September 6, 2026


Vulnerability identifier: #VU147166
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67276
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to open an SSH command channel as an authorized user.

The vulnerability exists due to improper verification of cryptographic signatures in the RouterOS SSH authorized-key matching logic when processing SSH authentication requests. A remote attacker can supply an RSA public key using an authorized modulus and an exponent of one to open an SSH command channel as an authorized user.

Note, the vulnerability is being actively exploited in the wild.


Affected software

MikroTik RouterOS

How to mitigate CVE-2026-67276

Install security update from vendor's website.

MikroTik RouterOS - addressed in versions 6.49.21, 7.23.4, 7.24.2

External References

Related Security Bulletins