CVE-2026-67279

MikroTik RouterOS — Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Affected

  • MikroTik/RouterOS < *..6.49.21
  • MikroTik/RouterOS < *..7.23.4
  • MikroTik/RouterOS < *..7.24.2
  • MikroTik/RouterOS range_unparsed *..<7.25 beta 3

Fixed in

  • MikroTik/RouterOS 6.49.21
  • MikroTik/RouterOS 7.23.4
  • MikroTik/RouterOS 7.24.2

Response & Mitigation

Why act now?

Prioritisation rationale

The CVSS v3 score of 6.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) materially understates operational risk: the authentication bypass requires no credentials, no user interaction, and no special network position, and CISA explicitly flags it as a prerequisite for chaining into CVE-2026-86060, which likely carries higher impact. The EPSS score of 0.71 % places this vulnerability in the 71st percentile — well above average exploitation likelihood relative to the full CVE population — and KEV listing confirms active exploitation is already occurring. MikroTik RouterOS is widely deployed in European mid-market and KRITIS environments as edge routers, VPN concentrators, and OT network gateways, making these devices high-value targets for initial access. Organisations with internet-facing or OT-adjacent RouterOS devices should treat this as a Priority 1 item and complete patching within 72 hours; those with devices reachable only from internal management networks should still patch within the next scheduled maintenance window and apply SSH ACL restrictions immediately.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch immediately: Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable). These are the only fixed releases for CVE-2026-67279. All devices running 6.0–6.49.20, 7.0–7.23.3, or 7.24–7.24.1 are vulnerable.
  • Restrict SSH access to management networks: Limit TCP/22 on all RouterOS devices to trusted management IP ranges immediately via /ip firewall filter or /ip service set ssh address=<mgmt-prefix>. Publicly reachable SSH is the direct attack surface.
  • Disable SSH if not operationally required: Run /ip service disable ssh. If SSH is needed, move it to a non-standard port and enforce strict ACLs as a temporary measure until patching is complete.
  • Assess chained exploit exposure: CISA notes that CVE-2026-67279 is used to chain into CVE-2026-86060. Immediately determine whether CVE-2026-86060 is also applicable to your devices and initiate parallel remediation.
  • Audit the RouterOS file namespace for tampering: The vulnerability allows unauthenticated file creation, overwrite, and reconstruction. Run /file print detail on all affected devices and compare against a known-good baseline — pay particular attention to configuration exports and support files.
  • Terminate unexpected SSH sessions: Check /ip ssh active-sessions print and immediately kill any sessions that cannot be attributed to authorised management activity.

Runbook · Step 2

Mitigation layers

  • Network segmentation — isolate the management plane: RouterOS devices must not be reachable via SSH from production networks or the internet. Route all management access through a dedicated out-of-band management VLAN or a VPN gateway.
  • Upstream firewall/IPS rule: Block inbound TCP/22 to RouterOS management IPs at the perimeter firewall or IPS. For detection-oriented rules: alert on SSH sessions where SSH2_MSG_KEXINIT (client-initiated rekey) is followed by SSH2_MSG_CHANNEL_OPEN and SSH2_MSG_CHANNEL_REQUEST (exec) without any intervening SSH2_MSG_USERAUTH_REQUEST — this matches the exploit's authentication-bypass sequence.
  • IAM hardening — enforce key-based authentication: Ensure all RouterOS accounts use strong credentials and SSH public-key authentication. Disable password-based SSH login: /ip ssh set always-allow-password-login=no. This does not patch the vulnerability but raises the bar for follow-on access.
  • Configuration integrity monitoring: Schedule automated RouterOS configuration exports (/export) to a write-protected external repository and diff against the previous snapshot on every run. Any unexpected delta should trigger an immediate alert.
  • Reduce overall service exposure: Disable all unused RouterOS services — Telnet, FTP, API, API-SSL, Winbox — via /ip service. Minimising the exposed attack surface limits lateral options if SSH is compromised.

Runbook · Step 3

Detection rules

  • Network telemetry (Zeek/Suricata): Monitor SSH connections to RouterOS devices on TCP/22 where a client-initiated rekey (SSH2_MSG_KEXINIT) is observed without prior SSH2_MSG_USERAUTH_REQUEST messages, followed by SSH2_MSG_CHANNEL_OPEN and an exec SSH2_MSG_CHANNEL_REQUEST. This sequence is the exploit fingerprint.
  • RouterOS syslog — unauthenticated file operations: Forward RouterOS system logs to your SIEM via syslog (/system logging action set remote). Alert on log entries containing file combined with created or overwritten where no corresponding authenticated session can be correlated.
  • Sigma rule shape (RouterOS syslog source):
    title: RouterOS Unauthenticated File Operation (CVE-2026-67279)
    logsource: { product: routeros, service: system }
    detection:
      keywords: ['file', 'ssh', 'exec']
      condition: keywords
    
  • KQL — SSH sessions without successful authentication: event.dataset:"zeek.ssh" AND NOT ssh.auth_success:true AND ssh.direction:"inbound" AND destination.port:22 — scope to RouterOS destination IPs. Any hit warrants immediate investigation.
  • File integrity baseline: Use the RouterOS API or a scheduled script to hash or timestamp critical files (config exports, support output) and compare against a stored baseline. Treat any deviation as a potential incident rather than a configuration drift event.

Description

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected operating systems

  • other

    mikrotik / routeros

Metrics

6.9
Source: cna-v4
62.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
1.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-09-05 20:17 UTC
CWE-841

Weakness classes (CWE)

  • CWE-841Class

    Improper Enforcement of Behavioral Workflow

    The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-26 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-67279","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
    • SSVC: {"id":"CVE-2026-67279","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  2. Modified Analysis2026-09-25 17:01 UTC· nvd@nist.gov
    • Reference Type: CISA-ADP: https://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chain Types: Third Party Advisory
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279 Types: US Government Resource
  3. CVE Modified2026-09-25 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://bishopfox.com/blog/mikrotrick-inside-the-routeros-takeover-chain
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279
    • SSVC: {"id":"CVE-2026-67279","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalI…
    • SSVC: {"id":"CVE-2026-67279","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  4. CVE CISA KEV Update2026-09-25 16:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-25
    • Due Date: 2026-09-25
    • Required Action: 2026-09-25
    • Vulnerability Name: 2026-09-25
  5. Initial Analysis2026-09-25 14:54 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
    • CPE Configuration: OR *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.49.21 *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.23.4 *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 7.24 up to (excluding) 7.24.2
    • Reference Type: CERT.PL: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve Types: Third Party Advisory
    • Reference Type: CERT.PL: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ Types: Mitigation, Third Party Advisory

Linked advisories