MikroTik RouterOS

12 known vulnerabilities in MikroTik RouterOS, 3 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-86060 CVSS 9.2 critical · actively exploited MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
  • CVE-2026-67279 CVSS 6.9 medium · actively exploited Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
  • CVE-2026-67277 CVSS 8.8 high · actively exploited MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

Latest vulnerabilities

  • CVE-2026-84411 CVSS 9.3 critical The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable…
  • CVE-2026-93345 CVSS 8.7 high MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing…
  • CVE-2026-89028 CVSS 8.2 high MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to…
  • CVE-2026-56719 CVSS 6.3 medium MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated…
  • CVE-2026-89021 CVSS 6.9 medium MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows…
  • CVE-2026-89020 CVSS 5.3 medium MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's…
  • CVE-2026-86060 CVSS 9.2 critical · actively exploited MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
  • CVE-2026-67281 CVSS 8.7 high RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale…
  • CVE-2026-67279 CVSS 6.9 medium · actively exploited Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
  • CVE-2026-67278 CVSS 6.3 medium MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and…
  • CVE-2026-67277 CVSS 8.8 high · actively exploited MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
  • CVE-2026-67276 CVSS 9.2 critical RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the…