MikroTik RouterOS SSH Authentication Bypass Vulnerability
Release Date: 6th September 2026 (Added 6th October 2026)
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-67279 is a vulnerability in the SSH service of MikroTik RouterOS caused by improper enforcement of the SSH protocol sequence (CWE-841). After a client-requested key re-exchange (rekey), the server moves into the SSH connection phase even though user authentication was never completed.
An unauthenticated attacker with network access to the SSH service (TCP/22) can then reach command and file-handling functions on the router, including creating or overwriting files in the router's managed namespace. The flaw is being actively exploited in the wild as part of a chain dubbed "MikroTrick".
What are the systems affected?
The following MikroTik RouterOS versions are affected:
RouterOS 6.x (long-term), from 6.0.0 prior to 6.49.21 – (Affected)
RouterOS 7.x (long-term), from 7.0.0 prior to 7.23.4 – (Affected)
RouterOS 7.x (stable) 7.24 and 7.24.1, prior to 7.24.2 – (Affected)
RouterOS 6.49.21 (long-term), 7.23.4 (long-term), 7.24.2 (stable), or later – (Not affected / patched)
What does this mean?
Successful exploitation may allow attackers to:
- Bypass SSH authentication on the router without valid credentials
- Create or overwrite files in the router's managed namespace, exposing configuration data and enabling persistent tampering
- When chained with CVE-2026-86060, gain full administrative control of the router and use it to monitor, redirect, or pivot into the networks behind it
Mitigation process?
CERTVU recommends the following:
-
Upgrade RouterOS Immediately
Upgrade to 6.49.21, 7.23.4, 7.24.2, or later. No workaround is documented; patching is the remediation. -
Restrict Management Access
Do not expose SSH to the internet. Limit SSH to trusted management networks or a VPN, and disable SSH where it is not needed. Also restrict the bandwidth-test service and web interfaces (WWW / WWW-SSL) from untrusted networks until patched. -
Hunt for Signs of Compromise
Review router logs and configuration for unexpected file creation, modification, or administrative changes consistent with exploitation. -
Rotate Credentials After Patching
Once the router is updated, rotate all administrative credentials as a precaution. -
Review the Related MikroTik Flaws
CVE-2026-86060 and CVE-2026-67277 are fixed in the same RouterOS releases; confirm the router is on a patched build for all of them.
Reference
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-67279
- Download advisory (English): MikroTik RouterOS SSH Authentication Bypass Vulnerability