Skip to content
Topic

Exploited vulnerabilities

Vulnerabilities in the CISA KEV catalog or actively exploited: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2026-86060
Security Critical · 9.8Exploited
CVE-2026-86060

Unauthorized command execution via SSH

CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.

2 min read
Illustrazione per CVE-2026-67277Security
CVE-2026-67277

Critical vulnerability in the RouterOS btest service

CVE-2026-67277 is a high-severity vulnerability (CVSS 8.2) that allows an unauthenticated client to cause a RouterOS kernel reboot via the Bandwidth Test (btest) service. The vulnerability affects versions prior to 6.49.21, 7.23.4, and 7.24.2 and was added to the CISA KEV catalog on September 10, 2026. You must immediately update the firmware to the fixed versions or disable the btest service if it is not in use.

High · 8.2Exploited
Illustrazione per CVE-2026-67279Security
CVE-2026-67279

SSH Vulnerability in RouterOS: Unauthenticated Access

CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, enabling the creation, overwriting, or reconstruction of files within the namespace managed by RouterOS. Versions prior to 6.49.21, 7.23.4, and 7.24.2 are affected. The vulnerability is listed in the CISA KEV catalog: you must update the firmware immediately.

Medium · 6.5Exploited
Illustrazione per CVE-2018-14847Security
CVE-2018-14847

WinBox Vulnerability in RouterOS

CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.

Critical · 9.1Exploited
Illustrazione per CVE-2018-7445Security
CVE-2018-7445

Buffer overflow in the SMB service of RouterOS

CVE-2018-7445 is a critical vulnerability (CVSS 9.8) in the SMB service of RouterOS that allows an unauthenticated attacker to execute code. It affects all RouterOS versions prior to 6.41.3. The vulnerability is listed in the CISA KEV catalog and requires applying updates according to the vendor's instructions.

Critical · 9.8Exploited