CVE-2026-67279
Overview
This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.
Vulnerability Description
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Impact
An attacker can gain unauthenticated access to the RouterOS file system namespace, enabling arbitrary file creation and modification. This includes overwriting configuration and diagnostic files, potentially leading to system manipulation or persistent compromise. No authentication or user interaction is required, making exploitation straightforward over the network. The result can be unauthorized configuration changes, data tampering, or disruption of router operations, impacting network security and availability.
Solution
Mikrotik has released patches addressing this vulnerability in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). Administrators should apply these updates promptly. Detailed patch instructions and advisory information are available at Mikrotik's official security advisory page: https://mikrotik.com/supportsec/september-2026-vulnerability/. No specific workarounds are documented; patching is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Mikrotik | Routeros | All |
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
|
|
|
Mikrotik | Routeros | All |
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
|
|
|
Mikrotik | Routeros | All |
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
13 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed — vendor: MikroTik, product: RouterOS
Active exploitation confirmed with 20 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.