Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-26 · updated: 2026-09-26 · tags: [cve] · confidence: medium · severity: medium · affected_sectors: [global] · au_impact: false

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request; on affected builds the server dispatches the command, enabling unauthenticated creation, overwrite and reconstruction of files in the RouterOS managed file namespace. CISA added CVE-2026-67279 to the Known Exploited Vulnerabilities catalog on 25 September 2026 on evidence of active exploitation, with a remediation deadline of 28 September. Its CVSS 4.0 base score is 6.9, which makes it the useful reminder that KEV urgency does not track severity: a medium-rated bypass carries the same three-day federal clock as the high-rated SharePoint code injection (CVE-2026-65660) added the same day.

Attribute Detail
CVE CVE-2026-67279
CVSS 6.9 (CVSS 4.0, MEDIUM)
Vendor / product MikroTik / RouterOS
Reported 2026-09-26