MikroTik RouterOS SSH Authentication Bypass Vulnerability

Release Date: 6th September 2026 (Added 6th October 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-67279 is a vulnerability in the SSH service of MikroTik RouterOS caused by improper enforcement of the SSH protocol sequence (CWE-841). After a client-requested key re-exchange (rekey), the server moves into the SSH connection phase even though user authentication was never completed.

An unauthenticated attacker with network access to the SSH service (TCP/22) can then reach command and file-handling functions on the router, including creating or overwriting files in the router's managed namespace. The flaw is being actively exploited in the wild as part of a chain dubbed "MikroTrick".

Reference

  1. https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-67279