MikroTik Network equipment company which makes routers, switches, access points, etc.
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any MikroTik product.
RSS Feeds for MikroTik security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in MikroTik products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by MikroTik Sorted by Most Security Vulnerabilities since 2018
Known Exploited MikroTik Vulnerabilities
The following MikroTik vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability |
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. CVE-2026-67279 |
September 25, 2026 |
| MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability |
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. CVE-2026-86060 |
September 10, 2026 |
| MikroTik RouterOS Missing Authentication for Critical Function Vulnerability |
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. CVE-2026-67277 |
September 10, 2026 |
| MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability |
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. CVE-2018-7445 Exploit Probability: 60.8% |
September 8, 2022 |
| MikroTik Router OS Directory Traversal Vulnerability |
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. CVE-2018-14847 Exploit Probability: 96.0% |
December 1, 2021 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 19 vulnerabilities in MikroTik with an average score of 7.4 out of ten. Last year, in 2025 MikroTik had 7 security vulnerabilities published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.99
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 19 | 7.44 |
| 2025 | 7 | 8.43 |
| 2024 | 1 | 0.00 |
| 2023 | 6 | 7.84 |
| 2022 | 11 | 8.03 |
| 2021 | 34 | 6.54 |
| 2020 | 5 | 5.65 |
| 2019 | 9 | 7.82 |
| 2018 | 7 | 7.87 |
It may take a day or so for new MikroTik vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent MikroTik Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-84411 | Oct 02, 2026 |
RouterOS Integer Underflow in HTTP Body Enables Root Code ExecThe web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. |
|
| CVE-2026-93345 | Sep 22, 2026 |
RouterOS <7.25beta4: Improper input validation in BGP VPN NLRI (Crash)MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device. The fix is carried only in 7.25beta4, a development build; the current stable release 7.24.2 and the current long-term release 7.23.5 both remain affected. |
|
| CVE-2026-89028 | Sep 16, 2026 |
MikroTik RouterOS <7.24 SMB1 Heap Corruption via uniPwdLen UnderflowMikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory. |
|
| CVE-2026-56719 | Sep 16, 2026 |
MikroTik RouterOS <7.24 SMB OOB Read VulnerabilityMikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents. |
|
| CVE-2025-56566 | Sep 16, 2026 |
Cleartext Credential Leak in Mikrotik RouterOS 7.19.4 via SPI Flash DumpMikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password. |
|
| CVE-2026-89021 | Sep 14, 2026 |
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractionMikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned. |
|
| CVE-2026-89020 | Sep 14, 2026 |
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder functionMikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership. |
|
| CVE-2026-86060 | Sep 05, 2026 |
RouterOS 6.x/7.x Privilege Escalation via Username Arg Flip in SSHRouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
|
| CVE-2026-67281 | Sep 05, 2026 |
RouterOS WebFig Unauth File-Read via /jsproxy Stale Pointer (6.49.21+)RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable) |
|
| CVE-2026-67279 | Sep 05, 2026 |
RouterOS SSH Rekey Escalation Enables Unauthenticated Exec in 6.x/7.xRouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
|