{
  "id": 8278591,
  "title": "Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers",
  "url": "https://urgent.news/2026/09/18/patching-guide-closing-the-cve-2026-67276-ssh-authentication-bypass",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T17:20:06.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/patching-guide-closing-the-cve-2026-67276-ssh-authentication-bypass-on-mikrotik-routers-3783"
  },
  "original_language": "en",
  "account": "The CVE-2026-67276 vulnerability affects MikroTik RouterOS routers with specific RouterOS versions. CERT-In has rated this flaw as CRITICAL, as it allows a forged RSA public key and signature during SSH authentication, potentially granting attackers full administrative control over the router.\n\nTo address this vulnerability, administrators should first identify affected devices by checking their RouterOS versions against the following lists: RouterOS 7.24 and earlier, RouterOS 7.0.0 to 7.23.3, and RouterOS 6.0.0 to 6.49.20.\n\nNext, administrators must upgrade MikroTik RouterOS to one of the following fixed releases: 7.24.2, 7.23.4, or 6.49.21 (or newer). Upgrading resolves not only CVE-2026-67276 but also two related issues: CVE-2026-86060, a privilege escalation vulnerability, and CVE-2026-67277, a denial-of-service and kernel-memory disclosure issue.\n\nWhile waiting to upgrade, it is advisable to reduce exposure by restricting SSH access to dedicated management networks or trusted source addresses, disabling SSH on devices that don't require it, disabling or firewalling the btest service if bandwidth testing is unnecessary, and logging/administering unexpected SSH login successes. However, the CERT-In advisory states that upgrading remains the only definitive fix for this vulnerability.",
  "summary": "Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers CERT-In rated CIVN-2026-0460 CRITICAL, and the reason is easy to state: CVE-2026-67276 lets a forged RSA public key and signature through SSH authentication, potentially handing the attacker full administrative control of the router. This guide condenses the advisory into the actions administrators should…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}