CVE-2026-67276: Bypassing SSH Authentication in MikroTik RouterOS
This text was generated using artificial intelligence (AI).CVE-2026-67276 affects SSH authentication in MikroTik RouterOS and has a CVSS score of 9.2 (CVSS 4.0). The vulnerability could allow an attacker to gain SSH command-line access as the target user without possessing the user’s private key. CERT Polska has reported active exploitation since September 2, 2026. MikroTik released security updates on September 3, 2026; CERT Polska coordinated the disclosure on September 5, 2026.
According to CERT Polska, when mapping an SSH request to an authorized RSA key, RouterOS verifies the key type and modulus, but not the exponent of the public key. The signature verification uses the key provided by the client.
If an attacker knows the modulus of an authorized RSA key, they can transmit a key with an exponent of one and generate a valid signature. This can result in SSH command-line access in the context of the target user without possessing the user's private key.
The vulnerability therefore affects RouterOS systems on which SSH is used for administration and where authorized RSA keys are stored.
Affected and Fixed RouterOS Versions
The following RouterOS versions are affected:
RouterOS 6.49.20 and earlier versions in this series
RouterOS 7.23.3 and earlier versions in this series
RouterOS 7.24.1 and earlier versions in this series
MikroTik lists the following corrected releases:
Long-term: RouterOS 6.49.21 and 7.23.4
Stable: RouterOS 7.24.2
Beta: RouterOS 7.25beta3
CERT Polska carried out the coordinated disclosure. The well-known attack chain involving CVE-2026-67276 and CVE-2026-86060 is known as „MikroTrick.“.
Actions for Affected Routers
1. Update RouterOS
Affected systems should be updated to a patched version of RouterOS. The update fixes the incorrect verification of the RSA key during SSH authentication.
2. Limit administrative services
SSH and other administrative services should be restricted to trusted networks. This helps limit access to administrative accounts in cases where an update cannot be performed immediately.
3. Check for signs of compromise
According to CERT Polska, it is advisable to check logs and user lists for unknown accounts. CERT Polska lists the following accounts as documented indicators: ops and -2. Among the known attacker IP addresses listed by CERT Polska are, among others, 82.192.72.4 and 103.102.31.18 on.
For compromised devices, it is recommended to perform a factory reset followed by a fresh setup. User accounts, authorized keys, and the configuration should be rechecked during this process.
Prioritizing Externally Accessible Systems
RouterOS devices with externally accessible SSH or other administrative services are particularly relevant for technical prioritization. The vulnerability requires knowledge of an authorized RSA modulus; however, it can bypass authentication without the corresponding private key.
The review should therefore first clarify:
Which MikroTik RouterOS devices are accessible within their own IP ranges?
On which devices is SSH accessible for administration?
Which RouterOS versions are used?
Which systems show anomalies in logs or user lists?
MikroTik routers are widely used in the SME and ISP sectors in Germany, Austria, and Switzerland. Organizations subject to the NIS 2 Directive—which has been implemented into law in Germany and Austria—should classify unpatched network devices as a reportable security risk. In Switzerland, the revised Information Security Act (ISG) applies, which mandates reporting to the BACS. If a data breach involving personal data occurs, the 72-hour reporting requirement under Article 33 of the GDPR also applies.
How LocateRisk Supports the Audit
LocateRisk identifies publicly accessible network devices and exposed management services. MikroTik RouterOS devices can be identified as network components on the external perimeter and prioritized for technical assessment.
The visibility of a RouterOS system or an SSH service does not indicate a specific vulnerable RouterOS version. However, it provides a basis for assigning accessible devices to the appropriate teams and for specifically checking their patch status.
In addition, continuous vendor risk monitoring can track security advisories issued by manufacturers. In the case of CVE-2026-67276, this approach links the manufacturer’s information to the question of whether MikroTik components are present in the organization’s externally accessible infrastructure.
Am I affected?
This affects MikroTik RouterOS in the versions listed above; the vulnerability has been fixed in versions 6.49.21, 7.23.4, 7.24.2, and 7.25beta3. If you want to know whether MikroTik RouterOS is even visible in your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
This affects RouterOS versions up to and including 6.49.20, 7.23.3, and 7.24.1. Fixed versions are 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), and 7.25beta3. Systems should be updated to one of these versions as soon as possible.
MikroTrick is the name given to a two-stage attack chain that combines CVE-2026-67276 (SSH authentication bypass) and CVE-2026-86060 (SSH privilege escalation). According to CERT Polska, chaining these two vulnerabilities allows an attacker to gain complete control over a RouterOS device whose SSH service is accessible from the Internet, without needing valid login credentials.
According to CERT Polska, unknown user accounts with the names ops or -2 as well as SSH connections from the following IP addresses 82.192.72.4 or 103.102.31.18 documented as indicators. Administrators should check user lists and logs for such entries. If a compromise is suspected, CERT Polska recommends performing a factory reset followed by a complete reinstallation of the device.
As of September 8, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-67276
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.