Vulnerability threat dossier

CVE-2026-67276

MikroTikRouterOS

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

VTP deterministic threat36.0of 100 · CVSS excluded

VTP analyst assessment

RouterOS SSH key-validation bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence94%
Public exploitation · VTP factCONFIRMED

Assessment

ENISA lists this RouterOS SSH flaw as actively exploited. An attacker who knows an authorized RSA modulus can forge an SSH signature by supplying a malformed public key. This can open an SSH command channel as the target user. Patch RouterOS and restrict SSH exposure.

Why it matters

  • The attacker needs an authorized RSA modulus and reachable SSH login service.
  • Successful exploitation can provide command execution as the targeted SSH user.
  • Public reporting describes RouterOS flaws being chained to hijack internet-exposed routers.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied reports describe a chain of RouterOS flaws and do not prove this CVE acted alone.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use RouterOS, install MikroTik's fixed release and limit SSH to trusted administration networks.

AI baseline history (6)
  1. BASELINE ASSESSED
    RouterOS SSH key-validation bypassgpt-5.6-terra · low
  2. BASELINE ASSESSED
    RouterOS SSH authentication bypass has reported exploitationgpt-5.6-terra · low
  3. BASELINE ASSESSED
    MikroTik RouterOS SSH key bypass is known to be exploitedgpt-5.6-terra · low
  4. BASELINE ASSESSED
    MikroTik RouterOS flaw publicly exploitedgpt-5.6-terra · low
  5. BASELINE ASSESSED
    RouterOS SSH authentication bypass with reported exploitationgpt-5.6-terra · low
  6. BASELINE ASSESSED
    MikroTik RouterOS vulnerability with reported exploitationgpt-5.6-terra · low
Technical severityCRITICALCVSS 9.2 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0016th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

ACTIVE EXPLOITATIONENISA EU KEV entry added
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

1 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-67276ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0005 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

MikroTik Patches Critical Flaws Chained to Hack Routers

Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek .

CVE-2026-67276CVE-2026-67277CVE-2026-67278CVE-2026-67279CVE-2026-67281CVE-2026-86060
Separate evidence group
Original

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

CVE-2025-12768CVE-2026-12663CVE-2026-13086CVE-2026-13380CVE-2026-13381CVE-2026-14540CVE-2026-15630CVE-2026-16675CVE-2026-19313CVE-2026-19315CVE-2026-19318CVE-2026-19471CVE-2026-19472CVE-2026-19949CVE-2026-20212CVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280CVE-2026-38577CVE-2026-42038CVE-2026-57909CVE-2026-57910CVE-2026-58048CVE-2026-58400CVE-2026-59346CVE-2026-59347CVE-2026-63219CVE-2026-64532CVE-2026-64533CVE-2026-6471CVE-2026-67276CVE-2026-67277CVE-2026-67278CVE-2026-67279CVE-2026-67281CVE-2026-67394CVE-2026-6881CVE-2026-73749CVE-2026-78174CVE-2026-80047CVE-2026-84115CVE-2026-84117CVE-2026-84118CVE-2026-84119CVE-2026-84120CVE-2026-84121CVE-2026-84122CVE-2026-84123CVE-2026-84124CVE-2026-84125CVE-2026-84126CVE-2026-84235CVE-2026-84352CVE-2026-84353CVE-2026-84645CVE-2026-84647CVE-2026-84648CVE-2026-84649CVE-2026-84650CVE-2026-84652CVE-2026-84665CVE-2026-84667CVE-2026-84668CVE-2026-84669CVE-2026-84670CVE-2026-84671CVE-2026-84672CVE-2026-84673CVE-2026-85046CVE-2026-86060CVE-2026-86206CVE-2026-86207CVE-2026-86218CVE-2026-9585CVE-2026-9586CVE-2026-9587CVE-2026-9588CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625CVE-2026-9633CVE-2026-9634CVE-2026-9637
Separate evidence group
Original

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]

CVE-2026-67276CVE-2026-67277CVE-2026-86060
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-67276

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-67276
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.0vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.05 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.2 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-347
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.