【Vulnerability Alert】MikroTik RouterOS Contains Three Critical Cybersecurity Vulnerabilities
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091401095555 | Publication Time | 2026-09-14 13:49:56 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 13:49:56 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】MikroTik RouterOS Contains Three Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000015 Network equipment manufacturer MikroTik has issued a critical cybersecurity advisory regarding three critical vulnerabilities affecting the RouterOS operating system. CVE-2026-67276 (CVSS 4.x: 9.2): When RouterOS matches an SSH authentication request against an authorized user's key, it does not compare the complete RSA public key. Instead, it checks the key type and modulus. If an attacker knows the authorized RSA modulus and forges a valid signature, the attacker may open an SSH command channel as the target user without possessing the private key. CVE-2026-86060 (CVSS 4.x: 9.2): A parameter handling vulnerability exists in the RouterOS SSH login path involving usernames that begin with a disabled character. This vulnerability allows an attacker to modify the trusted RouterOS policy mask, thereby resulting in privilege escalation. CVE-2026-67277 (CVSS 4.x: 8.8): RouterOS accepts a "related" btest session connection before authentication is completed. An unauthenticated client may exploit this state to initiate an IPv4 UDP test, which may cause RouterOS to restart. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
MikroTik RouterOS versions 7.24 to versions prior to 7.24.2 |
|||
|
[Recommended Actions] Please update to the following versions: MikroTik RouterOS version 7.25 beta3 or later |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





