Routeros
This hub aggregates every CVE we track for Routeros, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
109
CVEs tracked
10
Critical
37
High
4
In CISA KEV
Severity distribution
MEDIUM57HIGH37CRITICAL10LOW1
Monthly trend
0
0
0
0
1
0
0
1
2
1
0
1
1
0
0
0
0
0
0
3
0
2
0
11
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Routeros.
- CVE-2026-93345MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI7.5
- CVE-2026-89028MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX7.5
- CVE-2026-56719MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX6.5
- CVE-2026-89021MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction6.9
- CVE-2026-89020MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path4.3
- CVE-2026-86060SSH session privilege manipulation via a crafted username in Mikrotik RouterOSKEV9.8
- CVE-2026-67281Unauthenticated file read in Mikrotik RouterOS
- CVE-2026-67279SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
- CVE-2026-67278TLS server impersonation possible in Mikrotik RouterOS
- CVE-2026-67277Kernel memory disclosure and denial of service in MikroTik RouterOS btest serviceKEV8.2
- CVE-2026-67276SSH user impersonation possible in Mikrotik RouterOS
- CVE-2026-14227Insufficient session expiration in MikroTik RouterOS4.9
- CVE-2026-16347Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router8.8
- CVE-2024-27686Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.7.5
- CVE-2025-42611Improper certificate validation in multiple RouterOS services6.5
Product normalization is registry-driven with AI assist and human review. How it works