CVE-2026-67279: RouterOS SSH fails to resume auth after rekey
CVE-2026-67279 is a state-machine flaw in MikroTik RouterOS SSH: a rekey during authentication left the server in the channel phase without resuming login. Fixed in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21; chained with an argument-injection bug it yields full admin access.
- Fixes shipped in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21
- ZoomEye found 9,559 devices with reachable RouterOS SSH
- The flaw is the first half of the MikroTrick chain per CERT Polska
- Separate CVE-2026-67276 was wrongly linked to the chain
Read next
Security