Knox CVE Database
/
CVE-2026-67279
Medium
6.5

CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Added to the CISA KEV catalog:
September 25, 2026

Overview

MikroTik RouterOS contains a flaw in its SSH server state machine that allows an unauthenticated client to bypass the authentication phase entirely. By triggering a client-requested rekey during the SSH handshake, the server advances to the post-authentication session state without ever verifying credentials, accepting exec requests from the unauthenticated client. The attacker can then create, overwrite, or reconstruct files in the RouterOS managed file namespace. Versions across the 6.x and 7.x release lines are affected; fixes are available in 6.49.21, 7.23.4, and 7.24.2.

Vulnerability details

Affected vendor
MikroTik
Affected product
RouterOS
Weakness type (CWE)
CWE-841

CWE-841 describes a failure to enforce the expected sequence of operations in a behavioral workflow. In RouterOS, the SSH server maintains an internal state machine that should require completed user authentication before permitting session channels or command execution. The flaw causes the server to transition into the post-authentication state when a client requests a rekey, skipping the authentication step entirely. The server then treats the unauthenticated connection as authorized and dispatches exec requests it receives.


An attacker with network access to the SSH port sends a crafted SSH handshake that includes a client-initiated rekey, causing the server to skip authentication and open a session channel. From that position, the attacker can create, overwrite, and reconstruct files in the RouterOS managed file namespace, including configuration and diagnostic support files. CERT Polska confirmed this flaw can be chained with CVE-2026-86060 to achieve full unauthenticated administrative control. Active exploitation has been observed against internet-exposed devices.

Severity and impact

6.5
Medium
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
Low
Integrity impact
Low
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review RouterOS logs for the entry 'login failure for user -2 from <ip> via ssh', which the advisory identifies as a direct indicator of exploitation attempts against this flaw.
  • Check RouterOS logs and user lists for a newly created account named 'ops' or any 'user <name> added by ssh:-2@<ip>' entries, both confirmed post-exploitation artifacts per CERT Polska.
  • Run '/system/device-mode/print' and inspect the RouterOS log for a critical 'Flagged' entry, which the fixed releases write when the built-in compromise scanner detects known unauthorized configuration changes.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 28, 2026

Additional hardening

  • Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable); these releases correct the SSH state-machine flaw and add the built-in compromise scanner.
  • Restrict SSH access to explicitly trusted source IP addresses using RouterOS firewall rules; the vendor notes the default configuration blocks SSH from the internet, but any manual exposure must be closed or tightly filtered.
  • Replace exposed SSH management access with a WireGuard VPN tunnel and disable direct SSH reachability from untrusted networks, eliminating the attack surface this flaw requires.
  • After patching, audit the device for unknown users, scripts, scheduler tasks, proxy configurations, and tunnels; patching prevents new exploitation but does not remove access already established by an attacker.

Key dates

Published (NVD)
September 5, 2026
Added to CISA KEV
September 25, 2026
Remediation deadline
September 28, 2026
Last updated
September 26, 2026

References

Frequently asked questions

Does CVE-2026-67279 affect my FedRAMP authorization?

If MikroTik RouterOS runs inside your authorization boundary, CVE-2026-67279 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 28, 2026. An unpatched KEV within your boundary is an assessor finding: you remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-67279?

Knox does not patch MikroTik RouterOS on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-67279. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the opportunity to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-67279 isn't remediated by September 28, 2026?

If CVE-2026-67279 is not remediated by September 28, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the item and keeping your authorization clean is what protects that agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.