CVEs we hold for Mikrotik
Records whose assigning authority named Mikrotik as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-89021MikroTik RouterOS Path Traversal via Container OCI/tar Image ExtractionMikroTik RouterOS
CVE-2026-86060SSH session privilege manipulation via a crafted username in Mikrotik RouterOSMikrotik RouterOS
CVE-2026-67277Kernel memory disclosure and denial of service in MikroTik RouterOS btest serviceMikrotik RouterOS
CVE-2026-56719MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndXMikroTik RouterOS
CVE-2026-16347Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted RouterMikroTik Cloud Hosted Router
CVE-2025-6443Mikrotik RouterOS VXLAN Source IP Improper Access Control VulnerabilityMikrotik RouterOS
CVE-2025-10948MikroTik RouterOS libjson.so print parse_json_element buffer overflowMikroTik RouterOS
CVE-2024-2169Implementations of UDP application protocols are susceptible to network loops and denial of serviceMikroTik RouterOS-TFTP; Microsoft WDS; dproxy-nexgen
CVE-2023-32154Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution VulnerabilityMikrotik RouterOS
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.