{"api_version":"v1","generated_at":"2026-10-09T10:35:00+00:00","product":{"cve_count":16,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-mikrotik-routeros-f6309c896dca","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/routeros","name":"RouterOS","next_cursor":null,"observations":[{"affected":"RouterOS: < 7.24","affected_versions_present":true,"cve_id":"CVE-2026-84411","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84411","fixed":"RouterOS: 7.24","last_modified":"2026-10-03T15:52:53.879Z","patch_url":"https://mikrotik.com/download","primary_source":"","published":"2026-10-02T22:09:48.298Z"},{"affected":"RouterOS: \u2264 7.24.2","affected_versions_present":true,"cve_id":"CVE-2026-93345","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-93345","fixed":"RouterOS: 7.25beta4","last_modified":"2026-10-01T15:21:58.424Z","patch_url":"https://forum.mikrotik.com/t/7-25beta-development-is-released/272788","primary_source":"","published":"2026-09-22T17:07:49.359Z"},{"affected":"RouterOS: \u2264 6.49.18, 7.0.0 \u2264 7.11.2","affected_versions_present":true,"cve_id":"CVE-2026-89028","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89028","fixed":"RouterOS: 7.24.0","last_modified":"2026-10-01T15:21:51.527Z","patch_url":"https://forum.mikrotik.com/t/7-24-stable-is-released/272381","primary_source":"","published":"2026-09-16T13:12:02.672Z"},{"affected":"RouterOS: \u2264 6.49.18, 7.0.0 \u2264 7.11.2","affected_versions_present":true,"cve_id":"CVE-2026-56719","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56719","fixed":"RouterOS: 7.24.0","last_modified":"2026-10-01T15:20:03.940Z","patch_url":"https://forum.mikrotik.com/t/7-24-stable-is-released/272381","primary_source":"","published":"2026-09-16T13:07:38.839Z"},{"affected":"RouterOS: < 7.24.2","affected_versions_present":true,"cve_id":"CVE-2026-89021","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89021","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T15:21:49.680Z","patch_url":"","primary_source":"","published":"2026-09-14T18:06:31.966Z"},{"affected":"RouterOS: < 7.23.4, 7.24.0 < 7.24.2","affected_versions_present":true,"cve_id":"CVE-2026-89020","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89020","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T15:21:49.004Z","patch_url":"","primary_source":"","published":"2026-09-14T18:02:58.553Z"},{"affected":"RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21","affected_versions_present":true,"cve_id":"CVE-2026-86060","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86060","fixed":"The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been \u201cFlagged\u201d, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca .","last_modified":"2026-09-11T03:55:59.761Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060","primary_source":"","published":"2026-09-05T20:00:59.107Z"},{"affected":"RouterOS: 7.24 < 7.24.2, 7.20 < 7.23.4","affected_versions_present":true,"cve_id":"CVE-2026-67281","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67281","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-08T15:32:07.407Z","patch_url":"https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/","primary_source":"","published":"2026-09-05T20:00:58.457Z"},{"affected":"RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21","affected_versions_present":true,"cve_id":"CVE-2026-67279","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67279","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-26T03:55:45.145Z","patch_url":"https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/","primary_source":"","published":"2026-09-05T20:00:57.894Z"},{"affected":"RouterOS: 7.24 < 7.24.3, 7.0.0 < 7.23.6","affected_versions_present":true,"cve_id":"CVE-2026-67278","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67278","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T14:20:12.715Z","patch_url":"https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/","primary_source":"","published":"2026-09-05T20:00:57.258Z"},{"affected":"RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21","affected_versions_present":true,"cve_id":"CVE-2026-67277","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67277","fixed":"The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been \u201cFlagged\u201d, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca .","last_modified":"2026-09-11T03:55:58.675Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060","primary_source":"","published":"2026-09-05T20:00:56.614Z"},{"affected":"RouterOS: 7.24 < 7.24.2, 7.9 < 7.23.4","affected_versions_present":true,"cve_id":"CVE-2026-67276","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67276","fixed":"The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been \u201cFlagged\u201d, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca .","last_modified":"2026-09-09T04:26:19.218Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060","primary_source":"","published":"2026-09-05T20:00:55.811Z"},{"affected":"All versions","affected_versions_present":true,"cve_id":"CVE-2026-14227","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14227","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-30T19:15:52.381Z","patch_url":"","primary_source":"","published":"2026-07-30T17:39:59.616Z"},{"affected":"All versions","affected_versions_present":true,"cve_id":"CVE-2026-16347","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16347","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-29T13:57:56.713Z","patch_url":"","primary_source":"","published":"2026-07-28T19:59:29.927Z"},{"affected":"RouterOS: \u2264 7.20.x","affected_versions_present":true,"cve_id":"CVE-2025-42611","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-42611","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-05T12:49:47.495Z","patch_url":"","primary_source":"","published":"2026-05-05T10:58:36.937Z"},{"affected":"6.49.8","affected_versions_present":true,"cve_id":"CVE-2026-7668","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7668","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-20T07:33:30.897Z","patch_url":"","primary_source":"","published":"2026-05-02T20:00:15.044Z"},{"affected":"7","affected_versions_present":true,"cve_id":"CVE-2025-10948","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10948","fixed":"7.20.1; 7.21beta2","last_modified":"2025-10-13T16:58:49.425Z","patch_url":"https://vuldb.com/?id.325818","primary_source":"","published":"2025-09-25T14:02:07.376Z"},{"affected":"< 7.19.2","affected_versions_present":true,"cve_id":"CVE-2025-6563","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-6563","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-03T13:17:13.946Z","patch_url":"","primary_source":"","published":"2025-07-03T11:18:26.211Z"},{"affected":"7.15.3, 7.16.2","affected_versions_present":true,"cve_id":"CVE-2025-6443","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-6443","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-26T14:18:12.575Z","patch_url":"","primary_source":"","published":"2025-06-25T21:29:22.232Z"},{"affected":"6.49.7 Stable","affected_versions_present":true,"cve_id":"CVE-2023-32154","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32154","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-20T20:29:37.468Z","patch_url":"","primary_source":"","published":"2024-05-03T01:56:37.467Z"},{"affected":"6.49.9; 6.48.8","affected_versions_present":true,"cve_id":"CVE-2023-30800","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-30800","fixed":"6.49.10","last_modified":"2025-11-21T16:14:51.409Z","patch_url":"https://vulncheck.com/advisories/mikrotik-jsproxy-dos","primary_source":"","published":"2023-09-07T15:43:54.429Z"},{"affected":"< 6.49.7; \u2264 6.48.6","affected_versions_present":true,"cve_id":"CVE-2023-30799","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-30799","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-21T16:13:26.803Z","patch_url":"","primary_source":"","published":"2023-07-19T14:56:17.362Z"},{"affected":"Stable 6.43.12 and below; Long-term 6.42.12 and below; Testing 6.44beta75 and below","affected_versions_present":true,"cve_id":"CVE-2019-3943","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-3943","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T19:26:27.694Z","patch_url":"","primary_source":"","published":"2019-04-10T20:01:00.000Z"},{"affected":"n/a","affected_versions_present":true,"cve_id":"CVE-2018-14847","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-14847","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-21T23:45:49.372Z","patch_url":"https://github.com/BigNerd95/WinboxExploit","primary_source":"","published":"2018-08-02T07:00:00.000Z"},{"affected":"n/a","affected_versions_present":true,"cve_id":"CVE-2018-7445","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-7445","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-21T23:45:55.366Z","patch_url":"https://knvd.krcert.or.kr/info/vuln/notice/detail?id=6318b1f0d082fd0d2a52dbc5","primary_source":"","published":"2018-03-19T21:00:00.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Mikrotik"}}
