Urgent.News

What's breaking now, across thousands of outlets.

Tech

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers CERT-In rated CIVN-2026-0460 CRITICAL, and the reason is easy to state: CVE-2026-67276 lets a forged RSA public key and signature through SSH authentication, potentially handing the attacker full administrative control of the router. This guide condenses the advisory into the actions administrators should…

The CVE-2026-67276 vulnerability affects MikroTik RouterOS routers with specific RouterOS versions. CERT-In has rated this flaw as CRITICAL, as it allows a forged RSA public key and signature during SSH authentication, potentially granting attackers full administrative control over the router.

To address this vulnerability, administrators should first identify affected devices by checking their RouterOS versions against the following lists: RouterOS 7.24 and earlier, RouterOS 7.0.0 to 7.23.3, and RouterOS 6.0.0 to 6.49.20.

Next, administrators must upgrade MikroTik RouterOS to one of the following fixed releases: 7.24.2, 7.23.4, or 6.49.21 (or newer). Upgrading resolves not only CVE-2026-67276 but also two related issues: CVE-2026-86060, a privilege escalation vulnerability, and CVE-2026-67277, a denial-of-service and kernel-memory disclosure issue.

While waiting to upgrade, it is advisable to reduce exposure by restricting SSH access to dedicated management networks or trusted source addresses, disabling SSH on devices that don't require it, disabling or firewalling the btest service if bandwidth testing is unnecessary, and logging/administering unexpected SSH login successes. However, the CERT-In advisory states that upgrading remains the only definitive fix for this vulnerability.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Hollywood Wants the Duo

Page Six Hollywood: Ternus attended an intimate Apple party the night before the Emmys, filled with stars and powerbrokers, where some talent brazenly hit him up for the phone.

More from Friday 18 September →