Cyber & AI intelligence
Wasteland.
Briefs indexed2875
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-67279 2026-09-25

MikroTik RouterOS SSH Flaw CVE-2026-67279 Under Active Exploitation

"CISA has added CVE-2026-67279 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is in MikroTik RouterOS SSH. It lets an unauthenticated client open a session channel and run an exec request."

CISA has added CVE-2026-67279 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is in MikroTik RouterOS SSH. It lets an unauthenticated client open a session channel and run an exec request.

What Is It

CVE-2026-67279 is an improper enforcement of behavioral workflow vulnerability (CWE-841) in the RouterOS SSH service. According to NVD, if a client requests a rekey, RouterOS SSH moves into the connection protocol even though the client never attempted user authentication. The unauthenticated client can then open a session channel and send an exec request. On affected builds the server runs that command. An attacker can use this to create, overwrite and reconstruct files in the RouterOS managed file namespace without authenticating. That includes support files containing configuration and diagnostic data.

CISA notes that this vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Why It Matters

CISA added CVE-2026-67279 to the KEV catalog on 2026-09-25, which confirms active exploitation. CISA's SSVC assessment also records exploitation as "active", automatable as "yes" and technical impact as "partial". Whether ransomware campaigns have used it is listed as "Unknown".

NVD scores the flaw 6.5 (MEDIUM) under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). CERT Polska rates it 6.9 (MEDIUM) under CVSS 4.0. Attacks come over the network, need no privileges or user interaction and have low complexity.

What's Vulnerable

MikroTik RouterOS in these version ranges:

Patch Status

MikroTik has fixed the issue in:

CISA's required action is to apply mitigations according to vendor instructions and to follow BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements guidance. If mitigations are unavailable, organizations should follow the applicable BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must evaluate each asset's internet exposure. The federal remediation due date is 2026-09-28.

Sources