
Updates
Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.
FirmwareRouterOS 6.49.23 long-term: CVE-2026-84411 fix
MikroTik has released version 6.49.23 of the long-term channel for RouterOS 6. The update includes a critical security fix (CVE-2026-84411) and system stability improvements. Installation is recommended on all production devices using the conservative branch, after creating a full backup.
FirmwareRouterOS 7.23.8 long-term: fixes and security
MikroTik has released version 7.23.8 of the long-term channel, a conservative release designed for those who prioritize absolute stability. The update fixes a security vulnerability (CVE-2026-84411) and resolves several bugs related to IPsec, OSPF, and storage management. It is advisable to update production devices using the long-term branch after creating a full backup.
FirmwareRouterOS channels: stable, long-term, testing, and development. Which one to choose?
RouterOS is released on four channels: long-term (the most conservative branch, receiving only critical fixes), stable (the recommended current version), testing (release candidates for the next version), and development (beta releases). Use long-term or stable in production; testing and development are for the lab. You select the channel in /system package update; files for all versions, including old ones, are in the [RouterOS Archive](https://mikrotikdojo.com/tools/archivio-routeros/).
SecurityCritical vulnerability in RouterOS web service
CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.
FirmwareRouterOS 7.24.5: New Features and Fixes in the Stable Release
MikroTik has released version 7.24.5 of RouterOS on the "stable" channel. This release fixes regressions introduced in previous versions, improves stability on specific hardware models such as hAP be3 Media and CRS328-24P-4S+, and updates regulatory information for Wi-Fi. It is recommended for those using the stable branch in production.
SecurityDoS on BGP in RouterOS via NLRI VPN
CVE-2026-93345 is an improper input validation vulnerability in the routing service of MikroTik RouterOS that allows an unauthenticated attacker to crash the BGP service. Versions up to 7.24.2 are affected, including the long-term release 7.23.5; the fix is only present in the development version 7.25beta4. To mitigate the risk, restrict access to the BGP service to authorized peers only and monitor the availability of a corrected stable release.
FirmwareRouterOS 7.23.7 long-term: critical LTE fix and upgrade guide
MikroTik has released version 7.23.7 of the long-term channel to fix a severe regression introduced in 7.23.6 that caused the deletion of LTE module firmware on specific models. If you have upgraded to 7.23.6 or 7.24.3, you must immediately switch to 7.23.7 (or 7.24.4) and restore the modem firmware to recover connectivity.
AdvisoriesRouterOS 7.23.6 and 7.24.3: LTE warning for RBSXTLTE3-7 and SXTsq
MikroTik has issued a critical warning: do not update RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, and EG25-G&SXTsq devices to RouterOS versions 7.23.6 or 7.24.3. The update renders the LTE interface non-functional. If you have already updated, you must downgrade to 7.23.5 or 7.24.2 and update the modem firmware to restore connectivity.
SecurityOut-of-bounds Read in the SMB Daemon of RouterOS
CVE-2026-56719 is an Out-of-bounds Read vulnerability in the SMB daemon of MikroTik RouterOS. It affects versions up to 7.11.2 and 6.49.18, allowing an unauthenticated attacker to read sensitive memory via a manipulated SMB1 frame. Updating to version 7.24.0 resolves the issue; alternatively, disabling the SMB service eliminates the exposure.
SecurityHeap corruption in the SMB daemon of RouterOS
CVE-2026-89028 is a heap memory corruption vulnerability in the SMB daemon of RouterOS that allows a remote attacker to cause a denial of service. It affects versions up to 7.11.2 and 6.49.18; the fix is available in version 7.24.0. To mitigate the risk, you must update to 7.24.0 or disable the SMB service if not in use.
SecurityPath traversal in the RouterOS container package
CVE-2026-89021 is a path traversal vulnerability in the RouterOS container package that allows an authenticated attacker to write, delete, or create links to files outside the container root without starting it. It affects versions prior to 7.24.2; the fix is not planned for the 7.23.x long-term branch. If you use the container package in device-mode, update to a stable version 7.24.2 or higher, or disable the service.
SecurityStack-based buffer overflow in mtget (RouterOS)
CVE-2026-89020 is a stack-based buffer overflow vulnerability in the mtget binary of RouterOS that allows an authenticated user to crash the mtget worker process by sending a /tool fetch command with a TFTP path of 507 bytes or more. RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are affected. To protect yourself, you must update to one of the indicated fixed versions.