Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

MikroTik

Security flaws in MikroTik RouterOS and related networking products, used widely by ISPs and small businesses. Compromised edge routers hand attackers control over everything behind them.

5 CVEs1 articlesRSS
CVEs
CVE-2026-67279
[ MEDIUM ]CVSS 6.5EPSS 0.7%kev

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

MikroTik / RouterOS
CVE-2026-67277
[ HIGH ]CVSS 8.2EPSS 1.6%kev

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
CVE-2026-86060
[ CRITICAL ]CVSS 9.8EPSS 1.8%kev

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.

MikroTik / RouterOS
CVE-2018-7445
[ CRITICAL ]CVSS 9.8EPSS 60.8%kev

MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

MikroTik / RouterOS
CVE-2018-14847
[ CRITICAL ]CVSS 9.1EPSS 96.1%kev

MikroTik Router OS Directory Traversal Vulnerability

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

MikroTik / RouterOS
Articles