CISA Adds MikroTik RouterOS Vulnerability CVE-2026-67279 to Actively Exploited Vulnerabilities
CISA added MikroTik RouterOS vulnerability CVE-2026-67279 to the KEV catalog. Administrators are advised to update and restrict SSH access.

RouterOS CVE-2026-67279 was added on September 25, 2026, to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. agency CISA. The designation means that CISA has recorded its active exploitation. The flaw affects SSH in MikroTik RouterOS and, combined with another vulnerability, could lead to unauthenticated device exploitation.
CERT Polska states that the problem occurs after the SSH rekeying process. An unauthenticated client can then open a session channel and send an exec-type request. According to CISA, CVE-2026-67279 can be chained with CVE-2026-86060, creating a path to unauthenticated exploitation.
RouterOS CVE-2026-67279: Fixes are available
According to CERT Polska, fixes are available in RouterOS versions 6.49.21, 7.23.4, and 7.24.2. Administrators should verify which system branch they use and update devices to the corresponding fixed version.
MikroTik also recommends restricting SSH access to trusted networks only. This measure may serve as a temporary way to reduce exposure where an update cannot be deployed immediately, but it does not replace installing the fix.
Unpatched RouterOS devices accessible from the internet with SSH enabled are particularly at risk. Successful chaining with CVE-2026-86060 could result in unauthenticated takeover of the device. Since RouterOS is used at the network edge, compromise could give an attacker access to router administration and the rest of the network.
Configuration should be checked after updating
The vendor recommends checking after deploying the update whether the device contains unknown users, scripts, or configuration changes.
- update RouterOS to version 6.49.21, 7.23.4, or 7.24.2 according to the branch in use,
- restrict SSH to trusted networks only,
- check the device’s user accounts, scripts, and configuration,
- monitor new technical information and indicators of compromise from CISA, MikroTik, and CERT Polska.
Neither CISA nor the vendor has disclosed the scope of the attacks, the number of affected devices, or the attackers’ identities. Public materials also do not contain independent technical details of specific incidents in which CVE-2026-67279 itself was confirmed. CERT Polska previously warned about the exploitation of another vulnerability chain referred to as MikroTrick.
It will be important to see whether security organizations publish new technical information, indicators of compromise, or details about campaigns exploiting this vulnerability.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2026-67279 to KEV on September 25, 2026, active exploitation, and the possibility of chaining it with CVE-2026-86060.
- CERT Polska – Vulnerabilities in Mikrotik RouterOS software – Describes the technical mechanism of CVE-2026-67279, the affected RouterOS branches, and fixed versions.
- MikroTik – September 2026 vulnerability – Confirms the release of fixes and recommends restricting SSH to trusted networks and checking for possible signs of compromise.
- CERT Polska – Critical vulnerabilities in MikroTik RouterOS are being actively exploited – Confirms active attacks against internet-accessible RouterOS devices and provides checking and recovery procedures following possible compromise.
Verified and updated: September 26, 2026 06:25



