Updates
Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.

Unauthorized file read in WebFig
CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.
SecurityRSA Key Verification Flaw in SSH Server
RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.
SecurityFlawed RSA Signature in RouterOS: CVE-2026-67278
CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.
SecurityUnauthorized command execution via SSH
CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.
SecurityCritical vulnerability in the RouterOS btest service
CVE-2026-67277 is a high-severity vulnerability (CVSS 8.2) that allows an unauthenticated client to cause a RouterOS kernel reboot via the Bandwidth Test (btest) service. The vulnerability affects versions prior to 6.49.21, 7.23.4, and 7.24.2 and was added to the CISA KEV catalog on September 10, 2026. You must immediately update the firmware to the fixed versions or disable the btest service if it is not in use.
SecuritySSH Vulnerability in RouterOS: Unauthenticated Access
CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, enabling the creation, overwriting, or reconstruction of files within the namespace managed by RouterOS. Versions prior to 6.49.21, 7.23.4, and 7.24.2 are affected. The vulnerability is listed in the CISA KEV catalog: you must update the firmware immediately.
AdvisoriesRouterOS: security advisory and fixed versions
MikroTik has released a critical security update for RouterOS due to a recently discovered vulnerability. While most configurations are not at immediate risk, the update is strongly recommended for all users. The fixed versions include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21 (and later).
SecurityDenial of Service in libumsg.so of RouterOS
CVE-2026-39042 is an Integer Overflow or Wraparound vulnerability in the unflatten() function of the libumsg.so library that allows a remote attacker to cause a denial of service. It affects versions 7.21.x prior to v.7.21.4 and 7.22.x prior to v.7.22.2. You must update the firmware to the indicated corrective versions.
SecurityBuffer overflow in libjson.so of RouterOS 7
CVE-2025-10948 is a buffer overflow vulnerability in the parse_json_element function of the libjson.so component, reachable via the /rest/ip/address/print REST endpoint. It affects RouterOS 7 and can be exploited remotely. Updating to versions 7.20.1 or 7.21beta2 resolves the issue.
SecurityXSS in RouterOS Hotspot
CVE-2025-6563 is a cross-site scripting (XSS) vulnerability in the RouterOS hotspot service in versions prior to 7.19.2. An attacker can inject JavaScript code via the dst parameter to execute scripts in the victim's browser upon login. To mitigate the risk, you must update to version 7.19.2 or later.
SecurityBypass firewall IPv6 UDP in RouterOS 7
CVE-2023-47310 is a default configuration vulnerability in MikroTik RouterOS 7 that allows IPv6 UDP traceroute packets to bypass the firewall. It affects versions prior to 7.14. The mitigation is to update to RouterOS 7.14 or later.
SecurityVXLAN Vulnerability in RouterOS: CVE-2025-6443
CVE-2025-6443 is an improper access control vulnerability (CWE-284) in the VXLAN service of MikroTik RouterOS that allows a remote attacker, without authentication, to bypass access restrictions and reach internal network resources. Versions 7.15.3 and 7.16.2 are confirmed vulnerable by CVE.org, while NVD indicates all versions prior to 7.20; the exact fixed version has not yet been announced. Those using VXLAN on untrusted networks must update the firmware as soon as it becomes available and verify the service configuration.
SecurityAccount Enumeration in Winbox on RouterOS
CVE-2024-54772 allows an attacker to identify valid usernames on a MikroTik router by analyzing differences in Winbox service response times. Affected versions include long-term 6.43.13 through 6.49.13 and stable 6.43 through 7.17.2. To mitigate the risk, upgrade to version 6.49.18 or later and restrict Winbox access to the management network.