SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67278

MEDIUM · CVSS 6.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MikroTik RouterOS is vulnerable to a flaw in its X.509 validation process, which improperly accepts malformed RSA/PKCS#1 v1.5 signatures. This weakness allows an attacker with control over an outbound TLS connection to forge trusted certificates for any hostname, leading to potential TLS server impersonation. Organizations using affected MikroTik RouterOS versions should prioritize updating to the fixed versions to mitigate the risk of exploitation.

CVE
CVE-2026-67278
Severity
MEDIUM
CVSS
6.3
EPSS
0.15%

Original NVD Description

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)