VENDOR

MikroTik vulnerabilities: CVEs, exploitation and patches

Every MikroTik CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-67278
    RouterOS RSA signature verification allows TLS/SSH impersonation MikroTik RouterOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  2. CVE-2026-67276
    RouterOS SSH RSA key validation authentication bypass MikroTik RouterOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  3. CVE-2026-67277
    RouterOS missing-auth btest service kernel crash and memory disclosure MikroTik RouterOS ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.2
  4. CVE-2026-86060
    RouterOS SSH login username handling lets unauthenticated users escalate privileges MikroTik RouterOS ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-67279
    Improper workflow enforcement in RouterOS SSH allows unauthenticated file writes MikroTik RouterOS ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    MEDIUM 6.5
5 CVEs · page 1 of 1