Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3374 articles · 210916 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-67278PATCHED
mikrotik · routeros

TLS server impersonation possible in Mikrotik RouterOS

Description

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected Products

VendorProductVersions
mikrotikrouteros7.24, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mikrotikrouteroscert_advisory90%

References

  • https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve(third-party-advisory)
  • https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/(technical-description)
  • https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/(exploit)
  • https://mikrotik.com/supportsec/september-2026-vulnerability/(vendor-advisory)
  • https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801(release-notes)
  • https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800(release-notes)

Related News (2 articles)

Tier B
BSI Advisories3h ago
[NEU] [kritisch] MikroTik RouterOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-67278 | MikroTik RouterOS up to 6.49.20/7.23.3/7.24.1 certificate validation
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
7.24.27.23.46.49.21
CWECWE-347
PublishedSep 5, 2026
Trending Score31
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-67276EXPKEV
SSH user impersonation possible in Mikrotik RouterOS
Trending: 104
NONECVE-2026-67277EXPKEV
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
Trending: 104
NONECVE-2026-86060EXPKEV
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Trending: 104
NONECVE-2026-67281
Unauthenticated file read in Mikrotik RouterOS
Trending: 31
NONECVE-2026-67279
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 5, 2026
Discovered by ZDM
Sep 5, 2026
Patch Available
Sep 7, 2026