THREAT OPS › Threat News › [NVD] CVE-2026-67278 — MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to
[NVD] CVE-2026-67278 — MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to
CVE-2026-67278 CVSS: None Published: 2026-09-05T20:17:18.257
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-67278cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67278