{"type":"bundle","id":"bundle--32663a12-3a9a-5432-972f-b5359d9f2962","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--d5ac6823-d8d8-5622-9a50-7ef2d0daa4a4","created":"2026-09-20T19:29:52.642Z","modified":"2026-09-20T19:29:52.642Z","name":"MikroTik RouterOS SSH key check allows user impersonation","description":"RouterOS does not compare the complete RSA public key when matching SSH auth — checking key type and modulus but omitting the exponent. An attacker who knows an authorized RSA modulus can forge a valid signature and open an SSH command channel as the target user. Fixed in 7.24.2, 7.23.4, and 6.49.21.","aliases":["CVE-2026-67276","MikroTrick"],"first_seen":"2026-09-05T20:00:55.811Z","last_seen":"2026-09-05T20:00:55.811Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"CERT.pl MikroTik RouterOS advisory","url":"https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve"},{"source_name":"NVD CVE-2026-67276","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67276"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-67276-mikrotik-routeros-mikrotrick-ssh-cluster"}]}]}