Improper Verification of Cryptographic Signature in MikroTik RouterOS - CVE-2026-67278
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate TLS servers.
The vulnerability exists due to improper verification of cryptographic signatures in the RouterOS X.509 validation logic when validating malformed RSA/PKCS#1 v1.5 signatures. A remote attacker can forge a trusted intermediate certificate for arbitrary hostnames to impersonate TLS servers.
Exploitation requires control of or the ability to redirect an outbound RouterOS TLS connection and relies on the trusted e=3 root CA.