Mikrotik
RouterOS
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This CVE identity is linked to the Lifecycle record RouterOS. Use that record for publisher support phases and retirement dates.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-84411 | 2 Oct 2026 | RouterOS: < 7.24 | RouterOS: 7.24 | Update reference ↗ |
| CVE-2026-93345 | 22 Sep 2026 | RouterOS: ≤ 7.24.2 | RouterOS: 7.25beta4 | Update reference ↗ |
| CVE-2026-89028 | 16 Sep 2026 | RouterOS: ≤ 6.49.18, 7.0.0 ≤ 7.11.2 | RouterOS: 7.24.0 | Update reference ↗ |
| CVE-2026-56719 | 16 Sep 2026 | RouterOS: ≤ 6.49.18, 7.0.0 ≤ 7.11.2 | RouterOS: 7.24.0 | Update reference ↗ |
| CVE-2026-89021 | 14 Sep 2026 | RouterOS: < 7.24.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-89020 | 14 Sep 2026 | RouterOS: < 7.23.4, 7.24.0 < 7.24.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86060 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21 | The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca . | Update reference ↗ |
| CVE-2026-67281 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.2, 7.20 < 7.23.4 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2026-67279 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2026-67278 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.3, 7.0.0 < 7.23.6 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2026-67277 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.2, 7.0.0 < 7.23.4, 6.0.0 < 6.49.21 | The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca . | Update reference ↗ |
| CVE-2026-67276 | 5 Sep 2026 | RouterOS: 7.24 < 7.24.2, 7.9 < 7.23.4 | The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin Footnote 1 and update/upgrade the affected devices to the following vendor-supported fixed versions: Affected product Affected versions Fixed versions RouterOS 6.x Versions prior to 6.49.21 Version 6.49.21 RouterOS 7.x Long-Term Versions prior to 7.23.4 Version 7.23.4 RouterOS 7.x Stable Versions prior to 7.24.2 Version 7.24.2 RouterOS Development Branch Versions prior to 7.25 beta 3 Version 7.25 beta 3 The Cyber Centre recommends following guidance provided by MikroTik Footnote 1 and CERT Polska Footnote 11 to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been “Flagged”, MikroTik recommends following the instructions provided by the status site Footnote 12 . The Cyber Centre also recommends organizations to: Determine the current version of software on each appliance. Prioritize patching for systems exposing SSH to the internet. Monitor authentication logs and network activity for indications of unauthorized access. After patching, verify that the appliance is running the updated version and review logs for unusual activity. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 13 with an emphasis on the following topics: Consolidate, monitor, and defend Internet gateways Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca . | Update reference ↗ |
| CVE-2026-14227 | 30 Jul 2026 | All versions | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-16347 | 28 Jul 2026 | All versions | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-42611 | 5 May 2026 | RouterOS: ≤ 7.20.x | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-7668 | 2 May 2026 | 6.49.8 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-10948 | 25 Sep 2025 | 7 | 7.20.1; 7.21beta2 | Update reference ↗ |
| CVE-2025-6563 | 3 Jul 2025 | < 7.19.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-6443 | 25 Jun 2025 | 7.15.3, 7.16.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-32154 | 3 May 2024 | 6.49.7 Stable | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-30800 | 7 Sep 2023 | 6.49.9; 6.48.8 | 6.49.10 | Update reference ↗ |
| CVE-2023-30799 | 19 Jul 2023 | < 6.49.7; ≤ 6.48.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-3943 | 10 Apr 2019 | Stable 6.43.12 and below; Long-term 6.42.12 and below; Testing 6.44beta75 and below | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2018-14847 | 2 Aug 2018 | n/a | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2018-7445 | 19 Mar 2018 | n/a | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.