CVE-2026-67279
published 2026-09-05CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated…
PriorityP185medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-09-28
Exploited in the wild
EPSS
1.03%
62.4th percentile
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | routeros | >= 6.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 6.0.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 7.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.0.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.24 < 7.24.2 | 7.24.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck6.9MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an
ghsa_unreviewed·2026-09-05
CVE-2026-67279 [MEDIUM] CWE-841 RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
VulDB
Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Connection Protocol improper authentication (EUVD-2026-72027)
vuldb·2026-09-05·CVSS 6.9
CVE-2026-67279 [MEDIUM] Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Connection Protocol improper authentication (EUVD-2026-72027)
A vulnerability, which was classified as very critical, was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. Affected by this vulnerability is an unknown functionality of the component SSH Connection Protocol. The manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-67279. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
VulnCheck
MikroTik RouterOS Improper Enforcement of Behavioral Workflow
vulncheck·2026·CVSS 6.9
CVE-2026-67279 [MEDIUM] MikroTik RouterOS Improper Enforcement of Behavioral Workflow
MikroTik RouterOS Improper Enforcement of Behavioral Workflow
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected: MikroTik RouterOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Expl
CISA
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
cisa·2026-09-25·CVSS 6.5
CVE-2026-67279 [MEDIUM] CWE-841 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Vulnerability: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Affected: MikroTik RouterOS
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible
No detection rules found.
No public exploits indexed.
Hackernews
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
blogs_hackernews·2026-09-26·CVSS 8.8
CVE-2026-65660 [HIGH] SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
CVE-2026-67279 (CVSS score: 6.9) - An improper enforcement of behavioral workflow vulnerabilit
Hackernews
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
blogs_hackernews·2026-09-23·CVSS 6.9
CVE-2026-67279 [MEDIUM] MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick , combines an SSH state-machine flaw ( CVE-2026-67279 ) with an argument-injection bug in the RouterOS login process ( CVE-2026-86060 ). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
As previously reported , CERT Polska warned o
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cvehttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800https://mikrotik.com/supportsec/september-2026-vulnerability/https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/https://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chainhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279
2026-09-05
Published
2026-09-25
Added to CISA KEV
Exploited in the wild