Threat Advisory

MikroTik RouterOS Flaw Lets Attackers Take Full Control Over SSH

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in MikroTik's RouterOS firmware, affecting various components such as the SSH server and client, bandwidth-test service, X.509 certificate handling code, and WebFig interface. The overall risk/impact is high due to the existence of an exploit chain that can take over devices without authentication over SSH. Affected version ranges include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21.

CVE-2026-67276 (CVSS 9.8 — Critical): A flaw in the implementation of RSA public key validation allows attackers to craft a private key that enables them to authenticate as a targeted user. This vulnerability stems from not comparing the entire public key presented by a user, making it possible for an attacker who knows the username and the public modulus of the user’s key to exploit this weakness.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in MikroTik's RouterOS firmware, affecting various components such as the SSH server and client, bandwidth-test service, X.509 certificate handling code, and WebFig interface. The overall risk/impact is high due to the existence of an exploit chain that can take over devices without authentication over SSH. Affected version ranges include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21.

CVE-2026-67276 (CVSS 9.8 — Critical): A flaw in the implementation of RSA public key validation allows attackers to craft a private key that enables them to authenticate as a targeted user. This vulnerability stems from not comparing the entire public key presented by a user, making it possible for an attacker who knows the username and the public modulus of the user’s key to exploit this weakness.[emaillocker id="1283"]

CVE-2026-86060 (CVSS 8.8 — High): A second SSH implementation mistake allows attackers to escalate privileges to root by crafting usernames with full administrative privileges on the underlying OS, taking advantage of special characters at the start of usernames.

These vulnerabilities collectively present a significant risk to MikroTik devices accessible from the internet, particularly those with SSH services enabled.

RECOMMENDATION:

We recommend you to refer below link: https://mikrotik.com/supportsec/september-2026-vulnerability

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu