🔐 CVE Alert

CVE-2026-67278

UNKNOWN 0.0

TLS server impersonation possible in Mikrotik RouterOS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

CWE CWE-347
Vendor mikrotik
Product routeros
Published Sep 5, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new unknown vulnerabilities affecting mikrotik routeros are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Mikrotik / RouterOS
7.24 < 7.24.2 7.0.0 < 7.23.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve cert.pl: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ npratley.net: https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ mikrotik.com: https://mikrotik.com/supportsec/september-2026-vulnerability/ forum.mikrotik.com: https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 forum.mikrotik.com: https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800

Credits

Sławomir Rozbicki (CERT.PL)