The dojo blog.
Vulnerabilities explained with the commands to protect yourself, RouterOS updates to know before installing them, news and products — in English, from official sources.

Session Management Flaw in RouterOS API
CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.
DojoNetwatch on MikroTik: Get Telegram Alerts When a Device Goes Down
Netwatch is the sentinel of RouterOS: it pings an address and, when it stops responding or comes back, runs a script. We use it to monitor a camera and the internet line, with alerts sent to Telegram, and we look at the thresholds and the behavior after a reboot that the manuals do not mention.
SecurityRouterOS API Vulnerability: Brute-Force Risk
CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.
ProductsRB5009UPr+S+OUT: MikroTik Outdoor PoE Router
The RB5009UPr+S+OUT is an outdoor industrial router with an IP66 enclosure, designed to ensure high power redundancy and solid performance in exposed environments. It features 9 power options, a quad-core ARM CPU, and a mixed network interface including Gigabit, 2.5G, and SFP+ 10G ports.
DojoConnect MikroTik to Telegram: Router Alerts on Your Phone
A router that messages you on Telegram when something happens is worth more than ten graphs reviewed the next day. In seven steps, we create the bot, find the chat_id, and write a reusable Telegram script. Other Dojo how-tos use it to send alerts: Netwatch, reboots, rogue DHCP.
ProductsIntercell 10 B38+B39: outdoor TDD-LTE base station
The Intercell 10 B38+B39 is an outdoor base station for TDD-LTE networks that operates simultaneously on bands 38 and 39. It is designed for operators and WISPs requiring extended coverage in NLOS (Non-Line-Of-Sight) scenarios with a compact footprint and low power consumption. The device supports carrier aggregation to double peak capacity.
SecurityDenial of Service in libumsg.so of RouterOS
CVE-2026-39042 is an Integer Overflow or Wraparound vulnerability in the unflatten() function of the libumsg.so library that allows a remote attacker to cause a denial of service. It affects versions 7.21.x prior to v.7.21.4 and 7.22.x prior to v.7.22.2. You must update the firmware to the indicated corrective versions.
NewsNew MikroTik SFP Modules for Fiber Optic Connections
MikroTik has introduced four new SFP and SFP+ modules to expand fiber optic connectivity options. These devices support speeds from 1G to 10G and are designed for backbone, campus, and ISP infrastructure. Prices start at $22 for multimode modules and go up to $139 for single-mode SFP+ pairs.
ProductsMikroTik CRS510-8XS-2XQ-IN: 100G Switch with 8 25G Ports
The MikroTik CRS510-8XS-2XQ-IN is a 100 Gigabit network switch designed to upgrade existing 10 or 25 Gigabit infrastructure. It stands out for its combination of two 100G QSFP28 ports and eight 25G SFP28 ports, hot-swap redundant power supplies, and backward compatibility with lower standards.
NewsMikroTik 60 GHz: PTP and PTMP backhaul for local WISPs
MikroTik has documented a real-world use case where local WISPs used 60 GHz solutions to create high-capacity backhaul. The project, implemented with Cooltech, used CubeG-5ac60ay Pair and Wireless Wire Dish for point-to-point and point-to-multipoint links. The implementation met bandwidth demand without requiring the adoption of other brands.
DojoBasic hardening of a MikroTik router with RouterOS 7
A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.
NewsPractical community examples: Doom on RouterOS and CAPman setup
The MikroTik newsletter presents two real-world use cases from the community. The first involves running the Chocolate Doom game inside a RouterOS container. The second illustrates a complex wireless configuration for environments with thick walls, using wAP indoor and outdoor units in CAPman mode.
ProductsMikroTik LAMP 5G R16: Outdoor 5G Device with eSIM
The MikroTik LAMP 5G R16 is a ruggedized outdoor 5G modem, designed for urban, port, and marine environments where network coverage varies. It stands out for its integrated omnidirectional antennas and native eSIM support, eliminating the need for physical antenna alignment or replacing traditional SIM cards.