Critical MikroTik RouterOS Flaw Lets Attackers Bypass SSH Authentication
India's CERT-In issued a critical advisory on September 16, 2026, flagging three vulnerabilities in MikroTik RouterOS, the most severe being CVE-2026-67276. The flaw stems from incomplete RSA public-key verification during SSH authentication, allowing an attacker to gain access using a forged key and signature without a valid account. Successful exploitation could hand an attacker full administrative control, enabling traffic interception, network pivoting, and persistent access. Affected versions include RouterOS 6.x before 6.49.21, 7.0–7.23 before 7.23.4, and 7.24 before 7.24.2, all of which received patches in MikroTik's September 2026 advisory. Administrators are urged to upgrade immediately or, as an interim measure, restrict SSH access to trusted hosts and firewall the management plane.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in