Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers
CERT-In rated CVE-2026-67276 in MikroTik RouterOS as critical: a forged RSA key and signature allow bypassing SSH authentication and gaining full administrative control. Fixes are in versions 7.24.2, 7.23.4, and 6.49.21.
- Affects RouterOS 7.24 and below 7.24.2, 7.0.0–7.23.3, 6.0.0–6.49.20
- Attack requires no credentials, only an accessible SSH port
- Same release fixes CVE-2026-86060 and CVE-2026-67277
- ZoomEye counted 8,085,078 devices with RouterOS on September 18, 2026
Read next
Security