chiprook
← Security
SecurityOctober 8, 2026, 09:00

CVE-2026-67278 in MikroTik RouterOS allows RSA signature forgery

CERT Polska disclosed CVE-2026-67278 in MikroTik RouterOS 7.x, where flawed RSA/PKCS#1 v1.5 verification lets attackers forge certificates and SSH host keys. Fixes ship in RouterOS 7.23.6 and 7.24.3, while 7.23.4 and 7.24.2 carry an incomplete patch.

CVE-2026-67278 in MikroTik RouterOS allows RSA signature forgery
#MikroTik#RouterOS
Read next
Security

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root

Security

CVE-2026-86060 in RouterOS: admin takeover without credentials

Security

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers

Security

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers