Jump to the main content block

【Vulnerability Alert】MikroTik RouterOS Contains Three Critical Cybersecurity Vulnerabilities

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091401095555 Publication Time 2026-09-14 13:49:56
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-14 13:49:56
Impact Level Low  
[Subject]
【Vulnerability Alert】MikroTik RouterOS Contains Three Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000015

Network equipment manufacturer MikroTik has issued a critical cybersecurity advisory regarding three critical vulnerabilities affecting the RouterOS operating system.

CVE-2026-67276 (CVSS 4.x: 9.2): When RouterOS matches an SSH authentication request against an authorized user's key, it does not compare the complete RSA public key. Instead, it checks the key type and modulus. If an attacker knows the authorized RSA modulus and forges a valid signature, the attacker may open an SSH command channel as the target user without possessing the private key.

CVE-2026-86060 (CVSS 4.x: 9.2): A parameter handling vulnerability exists in the RouterOS SSH login path involving usernames that begin with a disabled character. This vulnerability allows an attacker to modify the trusted RouterOS policy mask, thereby resulting in privilege escalation.

CVE-2026-67277 (CVSS 4.x: 8.8): RouterOS accepts a "related" btest session connection before authentication is completed. An unauthenticated client may exploit this state to initiate an IPv4 UDP test, which may cause RouterOS to restart.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

MikroTik RouterOS versions 7.24 to versions prior to 7.24.2
MikroTik RouterOS versions 7.9 to versions prior to 7.23.4
MikroTik RouterOS versions 6.0.0 to versions prior to 6.49.21

[Recommended Actions]

Please update to the following versions:

MikroTik RouterOS version 7.25 beta3 or later
MikroTik RouterOS version 7.24.2 or later
MikroTik RouterOS version 7.23.4 or later
MikroTik RouterOS version 6.49.21 or later

[Reference]

 https://www.twcert.org.tw/tw/cp-169-11197-4c916-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: