Urgent.News

What's breaking now, across thousands of outlets.

Tech

SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279

SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279 Vulnerability overview CVE-2026-67279 is, at its core, a protocol bookkeeping error. MikroTik's RouterOS SSH server failed to resume authentication after a rekey performed during the authentication phase, and moved instead into the channel phase. The defect was fixed in the September 2026 RouterOS releases and forms the…

CVE-2026-67279 represents a protocol bookkeeping error in MikroTik's RouterOS SSH server. During authentication, the server fails to resume after a rekey performed during the authentication phase and instead proceeds to the channel phase. This defect was addressed in September 2026 RouterOS releases. The vulnerability is part of the first stage of the MikroTrick chain described by CERT Polska.

The SSH protocol comprises transport, user authentication, and connection layers, with data protection by session keys. A rekey can be triggered during or after authentication, but the specification does not allow a rekey during authentication. The vulnerable server accepted an authentication-phase rekey and moved into the channel phase without resuming authentication, leaving channel requests honored.

The client would see a server skipping a step, while the server experienced a missing state transition. The exploitation requires SSH reachability and the ability to complete a key exchange and request a rekey. The flaw alone yields a channel without rights, not a shell or an identity. However, when combined with another defect, it can lead to a full administrative console.

The fix is available in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. This incident highlights the importance of state-machine vulnerabilities in protocol implementations and the need for patch verification rather than relying solely on scanner outputs. Affected devices number 9,559 according to ZoomEye measurements.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Dreizehn Tage Mining brachten mir 134 Sats. Warum ich trotzdem weitergebaut habe.

Bitcoin-MiningEin kleines Set an Mac-Tools für Menschen, die Bitcoin-Mining so sehen wollen, wie es wirklich ist — nicht wie es beworben wird. Dreizehn Tage. 56.559 akzeptierte Shares. 134 Satoshis.

  • User earned 134 Satoshis from mining for 13 days
  • Total earnings equivalent to 10 cents at current rate
  • App Balance shows honest mining profit on macOS

One command per task; the shell is the API

exec.command is a string. It runs under sh -c with the project's and the workspace root's node_modules/.bin on PATH , in the project's directory, with the environment you declared.

  • vx is a task runner and build cache for JavaScript monorepos
  • Every task is a single command with declared inputs and outputs
  • This model enables remote execution, isolation, and human-readable migration

invisible_playwright_mcp Pairs MCP With Stealth Firefox

invisible_playwright_mcp packages a browser agent as an MCP server and a local web UI, while its maintainer claims the underlying Firefox engine is undetected by anti-bot systems and CAPTCHAs.

  • Invisibleplaywrightmcp packages Firefox as undetectable browser agent
  • Provides standalone UI and MCP server for page interaction control
  • Configuration options include proxies, identities, persistent profiles

More from Friday 9 October →