CVE-2026-67276
published 2026-09-05CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus…
PriorityP182high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
6.45%
93.5th percentile
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | routeros | >= 7.24 < 7.24.2 | 7.24.2 |
| mikrotik | routeros | >= 7.9 < 7.23.4 | 7.23.4 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.2CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 signature verification (EUVD-2026-72024)
vuldb·2026-09-05·CVSS 9.2
CVE-2026-67276 [CRITICAL] Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 signature verification (EUVD-2026-72024)
A vulnerability classified as very critical was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. This impacts an unknown function. Executing a manipulation can lead to improper verification of cryptographic signature.
The identification of this vulnerability is CVE-2026-67276. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent.
ghsa_unreviewed·2026-09-05
CVE-2026-67276 [CRITICAL] CWE-347 RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent.
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
VulnCheck
MikroTik RouterOS Improper Verification of Cryptographic Signature
vulncheck·2026·CVSS 9.2
CVE-2026-67276 [CRITICAL] MikroTik RouterOS Improper Verification of Cryptographic Signature
MikroTik RouterOS Improper Verification of Cryptographic Signature
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected: MikroTik RouterOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation Reference
No detection rules found.
No public exploits indexed.
Hackernews
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
blogs_hackernews·2026-09-23·CVSS 6.9
CVE-2026-67279 [MEDIUM] MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick , combines an SSH state-machine flaw ( CVE-2026-67279 ) with an argument-injection bug in the RouterOS login process ( CVE-2026-86060 ). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
As previously reported , CERT Polska warned o
Checkpoint
14th September – Threat Intelligence Report
blogs_checkpoint·2026-09-14·CVSS 10.0
CVE-2026-72898 [CRITICAL] 14th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with t
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cvehttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800https://mikrotik.com/supportsec/september-2026-vulnerability/https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
2026-09-05
Published
Exploited in the wild