CISA Adds MikroTik RouterOS Vulnerability CVE-2026-67279 to Actively Exploited Vulnerabilities

CISA added MikroTik RouterOS vulnerability CVE-2026-67279 to the KEV catalog. Administrators are advised to update and restrict SSH access.

RouterOS CVE-2026-67279 was added on September 25, 2026, to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. agency CISA. The designation means that CISA has recorded its active exploitation. The flaw affects SSH in MikroTik RouterOS and, combined with another vulnerability, could lead to unauthenticated device exploitation.

CERT Polska states that the problem occurs after the SSH rekeying process. An unauthenticated client can then open a session channel and send an exec-type request. According to CISA, CVE-2026-67279 can be chained with CVE-2026-86060, creating a path to unauthenticated exploitation.

RouterOS CVE-2026-67279: Fixes are available

According to CERT Polska, fixes are available in RouterOS versions 6.49.21, 7.23.4, and 7.24.2. Administrators should verify which system branch they use and update devices to the corresponding fixed version.

MikroTik also recommends restricting SSH access to trusted networks only. This measure may serve as a temporary way to reduce exposure where an update cannot be deployed immediately, but it does not replace installing the fix.

Unpatched RouterOS devices accessible from the internet with SSH enabled are particularly at risk. Successful chaining with CVE-2026-86060 could result in unauthenticated takeover of the device. Since RouterOS is used at the network edge, compromise could give an attacker access to router administration and the rest of the network.

Configuration should be checked after updating

The vendor recommends checking after deploying the update whether the device contains unknown users, scripts, or configuration changes.

  • update RouterOS to version 6.49.21, 7.23.4, or 7.24.2 according to the branch in use,
  • restrict SSH to trusted networks only,
  • check the device’s user accounts, scripts, and configuration,
  • monitor new technical information and indicators of compromise from CISA, MikroTik, and CERT Polska.

Neither CISA nor the vendor has disclosed the scope of the attacks, the number of affected devices, or the attackers’ identities. Public materials also do not contain independent technical details of specific incidents in which CVE-2026-67279 itself was confirmed. CERT Polska previously warned about the exploitation of another vulnerability chain referred to as MikroTrick.

It will be important to see whether security organizations publish new technical information, indicators of compromise, or details about campaigns exploiting this vulnerability.

Sources

Verified and updated: September 26, 2026 06:25

Sharing