CVE CVE-2026-67278
Severity CRITICAL · CVSS 3.1 9.1 · CVSS 4.0 6.3
Weakness CWE-347
Affected versions < 7.23.6, < 7.24.3
First non-vulnerable version 7.23.6, 7.24.3 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-09-05

What is the CVE-2026-67278 vulnerability?

RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures in RSA-based services, including TLS/X.509 certificate validation and SSH host key authentication. Because the trust store includes a root CA with public exponent e=3, an attacker who controls or redirects an outgoing TLS connection can use the root’s public certificate—without the private key—to forge a trusted intermediate and issue certificates for arbitrary hosts, enabling TLS server impersonation. The same permissive verification also compromises RSA-based SSH authentication.

Which RouterOS versions are vulnerable?

The vulnerable versions are all those lower than 7.23.6 and lower than 7.24.3. The fixed versions are 7.23.6 (Long-term) and 7.24.3 (Stable). Releases 7.23.4 and 7.24.2 included an incomplete fix and remain vulnerable.

Is my router at risk?

A router is exposed if the SSH service is active and reachable from untrusted networks, or if the router makes outgoing TLS connections to external servers and an attacker can intercept or redirect that traffic. If the SSH service is restricted to the internal administration network and outgoing TLS connections are protected by adequate network controls, the risk is reduced but not eliminated until the update is applied.

Is the CVE-2026-67278 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in CISA’s KEV catalog and ENISA does not report it as exploited. There is no evidence of documented active exploitation in available sources.

How to protect the router from CVE-2026-67278?

Update RouterOS to version 7.23.6 (Long-term) or 7.24.3 (Stable). While waiting for the update, restrict access to the SSH service exclusively to the trusted administration network and consider disabling the service if not necessary. Ensure that outgoing TLS connections are protected by network controls that prevent traffic redirection to malicious servers.

Which RouterOS commands are needed to mitigate CVE-2026-67278?

Temporary mitigation: ssh service

The flaw affects the router’s SSH server. It must be reachable only from the administration network, or turned off if you do not use it.

/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2026-67278?

CVE-2026-67278 has a CVSS v3.1 score of 9.1 (CRITICAL) according to NVD and a CVSS v4.0 score of 6.3 (MEDIUM) according to CERT.PL.

Which versions fix CVE-2026-67278?

The corrective versions are 7.23.6 (Long-term) and 7.24.3 (Stable). Versions 7.23.4 and 7.24.2 contain an incomplete fix and do not fully resolve the vulnerability.

Is CVE-2026-67278 in the CISA KEV catalog?

No, CVE-2026-67278 is not present in the CISA KEV catalog as of the date of this article.

Is disabling the SSH service enough to mitigate CVE-2026-67278?

Disabling the SSH service reduces exposure to RSA-based SSH authentication, but the vulnerability also concerns the validation of TLS/X.509 certificates in outgoing connections. Updating to the correct version remains the complete mitigation.

What is the CWE weakness associated with CVE-2026-67278?

The associated weakness is CWE-347: Improper Verification of Cryptographic Signature.

Official sources