## Overview
CISA added CVE-2026-67279 to its Known Exploited Vulnerabilities (KEV) list on September 25, 2026. This vulnerability affects MikroTik RouterOS and poses a significant risk to users. The addition to the KEV list indicates a federal deadline for remediation. Evidence of exploitation has prompted this action.
## Technical Details
CVE-2026-67279 involves an improper enforcement of behavioral workflow in RouterOS SSH. When a client requests a rekey, the system enters the connection protocol without requiring user authentication. This flaw allows an unauthenticated client to open a session channel and send exec requests. Affected builds include versions prior to 6.49.21, 7.23.4, and 7.24.2. The vulnerability can be exploited to create, overwrite, and reconstruct files in the RouterOS managed file namespace, including critical configuration and diagnostic data.
## Impact
The impact of this vulnerability is severe. An attacker can execute commands without authentication, leading to unauthorized access and potential compromise of the device. This could allow for the manipulation of settings and data, which may disrupt network operations or expose sensitive information.
## Mitigation
Defenders must update their MikroTik RouterOS installations to versions 6.49.21, 7.23.4, or 7.24.2 immediately. Organizations should also review their network configurations and access controls to minimize the risk of exploitation. Regular monitoring and auditing of router logs can help detect any unauthorized activities.
CSURFACE Threat Sensor