VENDOR
MikroTik vulnerabilities: CVEs, exploitation and patches
Every MikroTik CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-67278
RouterOS RSA signature verification allows TLS/SSH impersonationCRITICAL 9.1
- PATCH AVAILABLE
-
CVE-2026-67276
RouterOS SSH RSA key validation authentication bypassHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67277
RouterOS missing-auth btest service kernel crash and memory disclosureHIGH 8.2
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-86060
RouterOS SSH login username handling lets unauthenticated users escalate privilegesCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67279
Improper workflow enforcement in RouterOS SSH allows unauthenticated file writesMEDIUM 6.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
5 CVEs · page 1 of 1