AI description
CVE-2026-67276 is an SSH authentication bypass vulnerability affecting MikroTik RouterOS. The flaw stems from an incomplete verification process of RSA public keys during SSH authentication. Specifically, RouterOS checks the key type and modulus but fails to compare the entire RSA public key, omitting the exponent. This oversight allows an attacker, who possesses knowledge of a user's public modulus, to forge a different key and successfully log in via SSH without needing the corresponding private key. This vulnerability has been actively exploited as part of a larger attack chain dubbed "MikroTrick" and has been addressed in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
- Description
- RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- Source
- cvd@cert.pl
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- cvd@cert.pl
- CWE-347
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
23
🔴 MikroTrick — MikroTik routers under active attack Attackers are exploiting CVE-2026-67276 + CVE-2026-86060 against Internet-exposed RouterOS devices. The chain https://t.co/RSJXdyWeNL #CVE #CVE202667276 #CVE202686060 #MikroTik #RouterOS #MikroTrick #CyberSecurity #Info
@stem__shop
6 Sept 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MikroTrick zero-day chain gives unauthenticated attackers admin control of MikroTik RouterOS via internet-exposed SSH (CVE-2026-67276 CVSS 9.2 + CVE-2026-86060). Patch and block WAN SSH now. #MikroTik #ZeroDay #CyberSecurity https://t.co/adE7FghxsF
@CyberWorldOps
6 Sept 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MikroTrick is live. https://t.co/aUq4IvI1fF just dropped 6 RouterOS bugs, already exploited in the wild. CVE-2026-67276 is a critical SSH pubkey auth bypass (CVSS 9.2). Patch now: 7.25beta3 / 7.24.2 / 7.23.4 / 6.49.21 PoC: https://t.co/SaxzbFOdAC Advisory:
@LandscapeThreat
6 Sept 2026
61 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
It took us 3 hours to rewrite the full pre-auth RCE MikroTrick chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) from the public advisory. https://t.co/4tmLd8aAFq
@TolmoHQ
6 Sept 2026
2212 Impressions
5 Retweets
13 Likes
6 Bookmarks
2 Replies
1 Quote
MikroTik RouterOS zero-day chain "MikroTrick" under active exploitation since Sept 2, combining SSH auth bypass (CVE-2026-67276, CVSS 9.2) and privilege escalation to deliver unauthenticated full admin access. Key findings: - CVE-2026-67276 abuses a flaw in RSA public key https
@DFIR_Radar
6 Sept 2026
185 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
MikroTrick lab PoC — CVE-2026-67276 (RouterOS SSH public-key auth bypass) https://t.co/qFygGgipfY
@Dinosn
6 Sept 2026
17418 Impressions
64 Retweets
276 Likes
189 Bookmarks
4 Replies
3 Quotes
CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC https://t.co/qFygGgipfY
@Dinosn
6 Sept 2026
823 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MikroTik “MikroTrick”CERT Polska found six RouterOS bugs. Two chained together give full admin with no password if SSH is on the public internet. They named the chain https://t.co/wi9xRV6P4y it works:CVE-2026-67276: SSH does not check the full RSA key. It checks type + modulu
@ichbinlucasv
6 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 #CVE-2026-67276: Critical SSH Authentication Bypass in MikroTik RouterOS Enables Unauthenticated Device Takeover + Video -Prediction: 📈 1 Positive | 📉 2 Negative https://t.co/wFgeVHS5mn Educational Purposes!
@UndercodeUpdate
6 Sept 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes