{
  "id": 13190867,
  "title": "SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279",
  "url": "https://urgent.news/2026/10/09/ssh-rekey-during-authentication-the-protocol-edge-case-behind-cve",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T19:40:40.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/onaeiuspkz/ssh-rekey-during-authentication-the-protocol-edge-case-behind-cve-2026-67279-8og"
  },
  "original_language": "en",
  "account": "CVE-2026-67279 represents a protocol bookkeeping error in MikroTik's RouterOS SSH server. During authentication, the server fails to resume after a rekey performed during the authentication phase and instead proceeds to the channel phase. This defect was addressed in September 2026 RouterOS releases. The vulnerability is part of the first stage of the MikroTrick chain described by CERT Polska. The SSH protocol comprises transport, user authentication, and connection layers, with data protection by session keys. A rekey can be triggered during or after authentication, but the specification does not allow a rekey during authentication. The vulnerable server accepted an authentication-phase rekey and moved into the channel phase without resuming authentication, leaving channel requests honored. The client would see a server skipping a step, while the server experienced a missing state transition. The exploitation requires SSH reachability and the ability to complete a key exchange and request a rekey. The flaw alone yields a channel without rights, not a shell or an identity. However, when combined with another defect, it can lead to a full administrative console. The fix is available in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. This incident highlights the importance of state-machine vulnerabilities in protocol implementations and the need for patch verification rather than relying solely on scanner outputs. Affected devices number 9,559 according to ZoomEye measurements.",
  "summary": "SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279 Vulnerability overview CVE-2026-67279 is, at its core, a protocol bookkeeping error. MikroTik's RouterOS SSH server failed to resume authentication after a rekey performed during the authentication phase, and moved instead into the channel phase. The defect was fixed in the September 2026 RouterOS releases and forms the…",
  "key_points": [
    "RouterOS SSH server has protocol bookkeeping error",
    "Rekey during authentication phase not handled correctly",
    "Fixed in September 2026 RouterOS releases"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}