CVE-2026-67279

MEDIUM CISA KEV Pub 05/09 Upd 26/09

Overview

This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.

Vulnerability Description

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Impact

An attacker can gain unauthenticated access to the RouterOS file system namespace, enabling arbitrary file creation and modification. This includes overwriting configuration and diagnostic files, potentially leading to system manipulation or persistent compromise. No authentication or user interaction is required, making exploitation straightforward over the network. The result can be unauthorized configuration changes, data tampering, or disruption of router operations, impacting network security and availability.

Solution

Mikrotik has released patches addressing this vulnerability in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). Administrators should apply these updates promptly. Detailed patch instructions and advisory information are available at Mikrotik's official security advisory page: https://mikrotik.com/supportsec/september-2026-vulnerability/. No specific workarounds are documented; patching is the recommended remediation.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (3)

Vendor Product Version CPE
mikrotik Mikrotik Routeros All cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
mikrotik Mikrotik Routeros All cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
mikrotik Mikrotik Routeros All cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Some sightings

Threat Feed

13 events
2026-09-26
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-25
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-25
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-09-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-23
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-05
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: MikroTik, product: RouterOS

Detected as Exploited in the Wild (20 sightings)

Active exploitation confirmed with 20 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Authentication Bypass
89% auth_bypass
Information Disclosure
54% info_disclosure
Privilege Escalation
35% privilege_escalation

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (10)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-67279
cert.pl
GitHub CVE third-party-advisory
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
cert.pl
GitHub CVE technical-description
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
npratley.net
GitHub CVE exploit
https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
mikrotik.com
GitHub CVE vendor-advisory
https://mikrotik.com/supportsec/september-2026-vulnerability/
forum.mikrotik.com
GitHub CVE release-notes
https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
forum.mikrotik.com
GitHub CVE release-notes
https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
forum.mikrotik.com
GitHub CVE release-notes
https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
bishopfox.com
NVD API Third Party Advisory
https://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chain
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279