CVE-2026-67276 affects MikroTik RouterOS on the 7.x branch, before versions 7.23.4 (Long-term) and 7.24.2 (Stable). NVD classifies it as CWE-347 (Improper Verification of Cryptographic Signature). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated September 5, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-67276 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, RouterOS’s SSH authentication logic does not fully validate a client-supplied RSA public key against the key it has on file for an authorized user when matching an incoming authentication request. We are deliberately not reproducing NVD’s own description of exactly which RSA key component is skipped or the specific technique that lets an attacker forge a valid signature without the private key; verified absent from this article. NVD states the practical consequence is that an attacker who already knows an authorized user’s RSA public-key material can open an SSH command channel as that user without possessing the corresponding private key — an authentication bypass, not merely a weakened check.
Evidence and confidence
- Medium confidence — the CWE-347 classification and the described mechanism trace to NVD alone in our current ingestion, corroborated by CERT.pl’s own advisory on actively exploited RouterOS vulnerabilities and by MikroTik’s own security advisory. The exploitation report traces to VulnCheck KEV alone.
- Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE, though a 15.7th percentile EPSS figure appears in our raw KEV feed data (a low relative percentile, notable given the confirmed active exploitation and CERT.pl corroboration).
No field is in conflict between our sources. Our source data does not carry a fixed-version field beyond NVD’s own statement that 7.23.4 (Long-term) and 7.24.2 (Stable) contain the fix.
Why this matters
An SSH authentication bypass on network infrastructure hardware is a high-value target regardless of missing CVSS scoring — RouterOS devices sit at network chokepoints, and an attacker who can authenticate as a legitimate user without the corresponding private key gains the same command-channel access that user has, including router configuration changes and traffic interception capability. That CERT.pl, a national CERT, published its own advisory independently of MikroTik’s disclosure is a meaningful corroboration signal for a VulnCheck-only KEV listing. RouterOS 7.x operators should prioritize upgrading to 7.23.4 LTS or 7.24.2 Stable.
Frequently Asked Questions
What is CVE-2026-67276? An incomplete cryptographic signature verification vulnerability (CWE-347) in MikroTik RouterOS 7.x before 7.23.4/7.24.2, allowing an attacker who knows an authorized user’s RSA public-key material to open an SSH session as that user without the corresponding private key.
Is CVE-2026-67276 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 5, 2026, independently corroborated by CERT.pl’s own advisory on actively exploited RouterOS vulnerabilities. CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion.
Do I need an account to exploit this? The attacker needs to already know the targeted user’s RSA public-key material (not the private key) — this is not exploitable by a party with no prior knowledge of the target’s key configuration.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? RouterOS 7.23.4 (Long-term) or 7.24.2 (Stable), per NVD and MikroTik’s own release announcements. This affects only the 7.x branch.
Weakness classification and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-67276, corroborated by CERT.pl’s advisory and MikroTik’s own security advisory. Exploitation status and the September 5, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.