Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000015
Network equipment vendor MikroTik has issued a critical security advisory: 3 critical security vulnerabilities exist in the RouterOS routing operating system.
CVE-2026-67276 (CVSS 4.x: 9.2): When RouterOS matches SSH authentication requests against authorized user keys, it does not compare the full RSA public key but checks the key type and modulus. If an attacker knows the authorized RSA modulus and forges a valid signature, they can open an SSH command channel as the target user without the private key.
CVE-2026-86060 (CVSS 4.x: 9.2): A parameter handling vulnerability exists in the SSH login path of RouterOS. This vulnerability involves usernames starting with a null byte, allowing an attacker to modify the trusted RouterOS policy mask, resulting in privilege escalation.
CVE-2026-67277 (CVSS 4.x: 8.8): RouterOS accepts a “related” btest session connection before authentication is complete. Hackers can exploit this state from an unauthenticated client to initiate an IPv4 UDP test, which may cause RouterOS to restart.