MikroTik RouterOS flaw allows TLS/SSH trust abuse, requires immediate patching
CERT Polska disclosed CVE-2026-67278, a vulnerability in MikroTik RouterOS 7.x, on September 5, 2026. The flaw is in RSA signature verification, allowing attackers to forge trusted certificates for TLS and weaken SSH authentication. An attacker could exploit this by redirecting a device's outbound connection to issue certificates for any domain without a private key. Affected versions are RouterOS 7.x from 7.0.0 before 7.23.6 and from 7.24 before 7.24.3. The issue is fully fixed in versions 7.23.6 and 7.24.3.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in