Security Update Advisory for MikroTik Products
MikroTik RouterOS Security Update Advisory
MikroTik has released a security update addressing several vulnerabilities in RouterOS. Users of these products should update to the latest version.
Affected Products and Versions
- CVE-2026-67276: RouterOS 7.24 Or later but earlier than 7.24.2; RouterOS 7.9 Or later but earlier than 7.23.4.
- CVE-2026-67277, CVE-2026-67279, CVE-2026-86060: RouterOS 6.0.0 Or later but earlier than 6.49.21; RouterOS 7.0.0 Or later but earlier than 7.23.4; RouterOS 7.24 Or later but earlier than 7.24.2.
- CVE-2026-67278: RouterOS 7.0.0 Through 7.23.4, RouterOS 7.24 Through 7.24.2.
- CVE-2026-67281: RouterOS 7.20 Or later but earlier than 7.23.4; RouterOS 7.24 Or later but earlier than 7.24.2.
Resolved Vulnerabilities
- CVE-2026-67276 is an SSH authentication bypass vulnerability in RouterOS.
- CVE-2026-67277 is a memory information leak and denial-of-service vulnerability in RouterOS via the bandwidth-test feature.
- CVE-2026-67278 is a TLS server impersonation vulnerability in RouterOS.
- CVE-2026-67279 is an arbitrary file manipulation vulnerability in RouterOS caused by SSH authentication bypass.
- CVE-2026-67281 is a pre-authentication arbitrary file read vulnerability in RouterOS.
- CVE-2026-86060 is an SSH session privilege escalation vulnerability caused by manipulation of the username.
Patch Information
Vulnerability Patches for these vulnerabilities have been provided via the latest updates. CVE-2026-67276, CVE-2026-67278, and CVE-2026-67281 have been fixed in RouterOS 7.23.4 And 7.24.2. CVE-2026-67277, CVE-2026-67279, CVE-2026-86060 have been fixed in RouterOS 6.49.21, 7.23.4, 7.24.2, And 7.25 Beta 3.
The reference site includes information on these vulnerabilities and update recommendations.