CVE CVE-2026-67279
Severity MEDIUM · CVSS 3.1 6.5 · CVSS 4.0 6.9
Weakness CWE-841
Affected versions < 6.49.21, < 7.23.4, < 7.24.2
First non-vulnerable version 6.49.21, 7.23.4, 7.24.2 (per branch)
Actively exploited YES — CISA KEV catalog since 2026-09-25
CISA Advisory none
Published 2026-09-05

What is the CVE-2026-67279 vulnerability?

The RouterOS SSH server enters the connection protocol phase after a rekey request sent by the client, even if user authentication has never been attempted. This behavior allows an unauthenticated client to open a session channel and send an exec request. In affected versions, the server executes the command, allowing the creation, overwriting, and reconstruction of files in the file system managed by RouterOS, including support files containing configuration and diagnostic data.

Which RouterOS versions are vulnerable?

The vulnerable versions are those lower than 6.49.21, 7.23.4, and 7.24.2. The indicated fixed versions are 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

Is my router at risk?

A router is exposed if the SSH service is active and reachable from untrusted networks. The defect specifically concerns the router’s SSH server: to reduce exposure, the service must be made reachable only from the administration network or disabled if not in use.

Is the CVE-2026-67279 vulnerability actively exploited?

Yes, the vulnerability is present in the CISA KEV catalog and was added on September 25, 2026. ENISA also reports it as exploited from the same date.

How to protect the router from CVE-2026-67279?

Update the firmware to versions 6.49.21, 7.23.4, or 7.24.2 depending on the installed series. Pending the update, limit access to the SSH service to the trusted administration network only, or disable it completely if not necessary.

Which RouterOS commands are needed to mitigate CVE-2026-67279?

Temporary mitigation: ssh service

The defect concerns the router’s SSH server. It must be made reachable only from the administration network, or turned off if you do not use it.

/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2026-67279?

CVE-2026-67279 has a CVSS v3.1 score of 6.5 (MEDIUM) according to NVD and a CVSS v4.0 score of 6.9 (MEDIUM) according to CERT.PL.

Does CVE-2026-67279 require authentication to be exploited?

No, CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, without user authentication ever being attempted.

Which versions fix CVE-2026-67279?

CVE-2026-67279 is fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

Is CVE-2026-67279 present in the CISA KEV catalog?

Yes, CVE-2026-67279 is present in the CISA KEV catalog and was added on September 25, 2026.

Official sources