CVE-2026-67279
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- Published Sep 5, 2026
- CVSS 6.9 medium
- 1.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
- A fix is available
Affected software
In the news
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild The Hacker News ·
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA ·
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key The Hacker News ·
- Mikrotik security advisory (AV26-887) – Update 2 Canadian Centre for Cyber Security ·