EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-72024

Severity: CRITICAL Base Score: 9.2 CVSS Version: 4.0

Vulnerability Description

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): High
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): None
▪ Subsequent Integrity Impact (SI): None
▪ Subsequent Availability Impact (SA): None

Affected Vendors & Systems

Vendor MikroTik

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

CERT-PL

EPSS Probability

0.25

Known Aliases
CVE-2026-67276 GHSA-j9wg-77fw-f22f
Published On

2026-09-05

Last Updated

2026-09-07

Exploited Since

2026-09-05