CVE-2026-67278 in MikroTik RouterOS allows RSA signature forgery
CERT Polska disclosed CVE-2026-67278 in MikroTik RouterOS 7.x, where flawed RSA/PKCS#1 v1.5 verification lets attackers forge certificates and SSH host keys. Fixes ship in RouterOS 7.23.6 and 7.24.3, while 7.23.4 and 7.24.2 carry an incomplete patch.
- Affected: RouterOS 7.0.0–7.23.5 and 7.24–7.24.2; fixed in 7.23.6 and 7.24.3
- Root cause is a root CA with public exponent e=3 in the device trust store
- Exploitation requires redirecting an outbound TLS connection to an affected build
- ZoomEye counted 9,559 RouterOS SSH assets on 23 September 2026
Read next
Security