CVE CVE-2026-67276
Severity HIGH · CVSS 3.1 8.1 · CVSS 4.0 9.2
Weakness CWE-347
Affected versions < 7.23.4, < 7.24.2
First non-vulnerable version 7.23.4, 7.24.2 (per branch)
Actively exploited Not in CISA KEV; ENISA reports it as exploited since 2026-09-05
CISA Advisory none
Published 2026-09-05
Discrepant sources known_exploited: CISA KEV → False, ENISA EUVD → True

What is the CVE-2026-67276 vulnerability?

The vulnerability consists of an incomplete cryptographic signature verification during SSH authentication. RouterOS checks the key type and modulus, but omits the comparison of the exponent. Since signature verification uses the key provided by the client, an attacker who knows the modulus of an authorized RSA key can provide a key with an exponent of one, forge a valid signature, and open an SSH command channel as the target user without possessing the private key.

Which RouterOS versions are vulnerable?

The vulnerable versions are all 7.x versions lower than 7.23.4 and 7.24.2. The corrective versions are 7.23.4 (Long-term) and 7.24.2 (Stable).

Is my router at risk?

A router is exposed if the SSH service is active and reachable from untrusted networks. If SSH access is limited to the internal administration network only, or if the service is disabled, the risk of remote exploitation is reduced.

Is the CVE-2026-67276 vulnerability actively exploited?

CISA does not include this vulnerability in the KEV catalog, while ENISA reports it as exploited starting from September 5, 2026. The cited sources report a discrepancy on this point: CISA indicates it is not exploited, ENISA indicates it is.

How to protect the router from CVE-2026-67276?

Update RouterOS to version 7.23.4 (Long-term) or 7.24.2 (Stable). Alternatively, limit access to the SSH service to trusted networks only via firewall rules, or disable it if not necessary.

Which RouterOS commands are needed to mitigate CVE-2026-67276?

Temporary mitigation: ssh service

The defect concerns the router’s SSH server. It must be made reachable only from the administration network, or turned off if you do not use it.

/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation restarts the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2026-67276?

The CVSS v3.1 score assigned by NVD is 8.1 (HIGH). The CVSS v4.0 score assigned by CERT.PL is 9.2 (CRITICAL).

Does CVE-2026-67276 require authentication to be exploited?

No, the vulnerability does not require prior privileges. The attacker can exploit the defect without authenticating, by providing a public key with an exponent of one and forging the signature.

Is disabling SSH enough to mitigate CVE-2026-67276?

Yes, disabling the SSH service or making it inaccessible from untrusted networks eliminates the remote attack vector described in the vulnerability.

What is the CWE classification of CVE-2026-67276?

The vulnerability is classified as CWE-347: Improper Verification of Cryptographic Signature.

Official sources