← All Advisories

MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-67278

Key Details

CVECVE-2026-67278
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsMikroTik RouterOS
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MikroTikRouterOS
SubsystemsIndustrial Network - Routers/Firewalls
SectorsMulti-sector

What to Know

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. The same permissive verification also undermines RSA-based SSH authentication.

This issue affects only 7.x branch was fixed in versions: 7.23.6 (Long-term) and 7.24.3 (Stable).

Releases 7.23.4 and 7.24.2 included an incomplete fix. (NVD)

What to Do

Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67278
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-67278
Vendor advisoryhttps://mikrotik.com/supportsec/september-2026-vulnerability/