What changes in RouterOS 7.23.8?
The release introduces a critical security fix in the system subsystem, identified as CVE-2026-84411. In terms of stability, it resolves an issue that caused indefinite flash storage growth during dynamic configuration changes. Regarding routing and communication security, it fixes IPsec tunnels that failed to establish when an address my-id was configured on the responder, and an OSPF bug where unset interface parameters were not applied correctly.
In the wireless sector, it fixes a defect in management frames that incorrectly advertised the availability of multiple 6 GHz access points, and updates radio regulatory data. Other fixes include the console output for /system/identity/print (a regression introduced in v7.23.6), incorrect WAN interface selection in QuickSet, and improved Ethernet stability when forcing an unsupported link speed.
Who should update (or not)?
This release is intended exclusively for administrators using the long-term channel, meaning those who require maximum reliability for critical infrastructure. It is not a testing or development version: it is the current recommended release for those operating in this conservative branch. If you are using stable, testing, or development channels, this version does not directly concern you, but the security fixes may also be present in the other branches in their respective equivalent versions.
How to update (or remediate) safely?
Before proceeding, create a backup or an export file and save it to an external storage device. Verify that the router has sufficient free space to download all RouterOS packages and ensure that power is not interrupted during the process. To update, go to the System/Packages menu, click Check For Updates, and select the long-term channel in the RouterOS configuration interface. Alternatively, download the packages from the official MikroTik download page.
Official changelog for 7.23.8 (2026-10-08)
The complete list of changes, as published by MikroTik (9 items, in English).
Show/hide changelog
consolefix console output of /system/identity/print being split into multiple lines (introduced in v7.23.6)ethernetimproved stability when forcing unsupported link speedipsecfix IPsec tunnels not establishing when an address my-id is configured on the responderospffix unset interface template parameters not being applied to interfacesquicksetfix the WAN interface being selected incorrectlysystemimprove stability (includes CVE-2026-84411)systemstop the flash configuration store from growing on dynamic configuration changeswififix malformed management frame information elements advertising availability of multiple 6GHz APswifiupdate radio regulatory information
Download RouterOS from the MikroTik site All changelogs
Frequently asked questions
Does RouterOS 7.23.8 fix security vulnerabilities?
Yes, RouterOS 7.23.8 includes the fix for CVE-2026-84411 in the system subsystem. This is one of the main reasons to apply the update to production devices using the long-term channel.
Why did IPsec tunnels fail to establish before 7.23.8?
The issue was caused by configuring an address my-id on the responder. Version 7.23.8 corrects this behavior, allowing IPsec tunnels to establish correctly in this specific configuration.
Does RouterOS 7.23.8 resolve the flash storage issue?
Yes, the update prevents the flash configuration store from growing indefinitely when dynamic changes are made to the configuration. This prevents potential storage space exhaustion over time.
Which regressions were fixed in 7.23.8?
The release fixes an issue in the console output for /system/identity/print, which was introduced in version v7.23.6 and caused the output to be split across multiple lines.
How do you access the long-term channel for updates?
To update via the graphical interface, select the long-term channel in the System/Packages menu before clicking Check For Updates. Alternatively, you can manually download the packages from the MikroTik download page.



