{
  "id": 8321608,
  "title": "MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication",
  "url": "https://urgent.news/2026/09/18/mikrotik-routeros-cve-2026-67276-forged-rsa-keys-can-bypass-ssh",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T21:40:08.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/mikrotik-routeros-cve-2026-67276-forged-rsa-keys-can-bypass-ssh-authentication-540n"
  },
  "original_language": "en",
  "account": "MikroTik RouterOS is facing a critical security vulnerability, CVE-2026-67276, which can allow attackers to bypass SSH authentication by forging RSA keys. CERT-In issued a security advisory on September 16, 2026, rating the flaw as critical. The vulnerability lies in RouterOS's incomplete verification of RSA public keys during SSH authentication. An attacker can exploit this by sending a crafted public-key authentication request with a forged RSA key and signature, which the router accepts. This bypass of authentication could potentially grant the attacker full administrative control over the device. To mitigate the risk, administrators are advised to upgrade RouterOS to version 7.24.2, 7.23.4, or 6.49.21 or later. As an interim measure, restricting SSH access to trusted hosts, disabling the SSH service when not in use, and implementing firewall rules for the management plane can also help. The vulnerability also affects RouterOS versions 7.0.0 through 7.23.3 and 6.0.0 through 6.49.20. In addition to CVE-2026-67276, the fix in this release addresses two other vulnerabilities, CVE-2026-86060 and CVE-2026-67277.",
  "summary": "MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication CERT-In issued CIVN-2026-0460 on September 16, 2026 with a CRITICAL rating for three MikroTik RouterOS flaws. The most serious of them, CVE-2026-67276, breaks the trust model of SSH public-key authentication. An attacker who can reach the SSH login path of an affected router can send a crafted public-key…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}