External risk intelligence

MikroTik RouterOS Unauthenticated File Manipulation Vulnerability

CVE advisoryKnown Exploit

CVE-2026-67279

This vulnerability affects the SSH service on MikroTik RouterOS. RouterOS is a network operating system for routers and gateways, and the SSH interface is a standard management surface commonly exposed on the internet for remote administration and configuration.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a security vulnerability in MikroTik RouterOS that could allow an unauthenticated user to execute commands on affected devices. The issue lies in how the system handles a specific connection rekey process, potentially enabling unauthorized file modifications, including critical configuration and diagnostic data. The main concern is confirming relevance and exposure to this type of network device.

  • Unauthenticated command execution via network.
  • Affects network devices crucial for connectivity.
  • Verify if your network devices are impacted.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication by exploiting how the SSH service handles connection rekeys before user login. This allows them to establish a session and execute commands, leading to unauthorized file modifications.

  • Unauthenticated network access required.
  • SSH rekey after connection initiation.
  • Unauthorized file creation/modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated client to execute commands on a MikroTik router. Under certain conditions, an attacker might be able to create, overwrite, or reconstruct files within the router's file system, potentially affecting configuration and diagnostic data.

  • Router configuration and diagnostic files.
  • Unauthenticated session channel allows command execution.
  • Disruption of router operations and data integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for network infrastructure and device management, such as network operations, security operations, and platform engineering, should take the lead on addressing this vulnerability. The first practical step is to identify all MikroTik RouterOS devices within the environment, determine their internet exposure and business criticality, and then locate the accountable owner for each device to plan remediation based on the assessed risk.

  • Network and security teams own the resolution.
  • Verify internet-facing RouterOS device exposure.
  • Plan and execute updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MikroTik RouterOS?

RouterOS is a network operating system developed by MikroTik. It serves as the primary software platform for their hardware, such as routers, switches, and wireless access points, providing the core routing, firewall, and management features necessary to control network traffic and connectivity.

What does CWE-841 mean for CVE-2026-67279?

CWE-841 refers to 'Improper Enforcement of Behavioral Workflow.' In this context, it means the RouterOS SSH service fails to follow the correct sequence of operations. Specifically, it proceeds to handle commands after a client requests a rekey, even though the user has not yet successfully authenticated, bypassing the intended security flow.

How is this vulnerability triggered?

An attacker triggers this by initiating an SSH connection and requesting a rekey before attempting any authentication. If the device is running an affected version, the system incorrectly opens a session channel, allowing the attacker to send commands to create, overwrite, or reconstruct files in the router's file system.

Is my device at risk if it is not exposed to the internet?

Halo Surface Signal notes that while SSH is often exposed for remote management, the risk profile changes based on your setup. Any device on your network that accepts SSH connections is technically susceptible, but devices reachable from the internet face the highest risk because they are accessible to a wider range of potential attackers.

What should I do to address CVE-2026-67279?

The most effective response is to update your devices to a non-affected version, such as 6.49.21, 7.23.4, or 7.24.2. Start by creating an inventory of all your MikroTik hardware, identifying which are running vulnerable versions, and prioritizing updates for those that are internet-facing.

References