PatchSiren

MikroTik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MikroTik CVE published 2026-07-30

CVE-2026-14227

An executive overview of CVE-2026-14227: MikroTik RouterOS products with the API enabled are vulnerable to Insufficient Session Expiration due to a session-management flaw. This allows active sessions to retain previous permissions after inactivity timeouts or user-group changes, potentially letting users with reduced permissions access information. Administrators should verify affected systems, ensure pr [truncated]

HIGH MikroTik CVE published 2026-07-28

CVE-2026-16347

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T06:00:00.000Z and has not been modified since then. The MikroTik RouterOS and Cloud Hosted Router contain a weakness in their API authentication handling. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures [truncated]

Review MikroTik CVE published 2026-07-13

CVE-2026-39042

A denial of service vulnerability exists in MikroTik RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2. The issue is caused by the unflatten() function in libumsg.so. This vulnerability could potentially allow a remote attacker to cause a denial of service. Limited information is available about this vulnerability, and additional review is necessary to understand the full impact.

MEDIUM MikroTik CVE published 2026-05-02

CVE-2026-7668

A medium-severity out-of-bounds read vulnerability exists in MikroTik RouterOS 6.49.8 within the SCEP Endpoint component. The flaw resides in the ASN1_STRING_data function in nova/lib/www/scep.p, where manipulation of the transactionID or messageType arguments can trigger memory access beyond allocated bounds. The attack vector is network-accessible and requires no authentication, though the CVSS 4.0 vect [truncated]

Known exploited MikroTik CVE published 2022-09-08

CVE-2018-7445

CVE-2018-7445 is a MikroTik RouterOS stack-based buffer overflow that CISA placed in the Known Exploited Vulnerabilities catalog on 2022-09-08, with a remediation due date of 2022-09-29. Organizations running RouterOS should treat this as a high-priority patching item and verify that vendor-recommended updates are applied.

Known exploited MikroTik CVE published 2021-12-01

CVE-2018-14847

CVE-2018-14847 is a MikroTik RouterOS directory traversal vulnerability that CISA has included in the Known Exploited Vulnerabilities catalog. The KEV listing is the key defensive signal here: it indicates known exploitation and directs defenders to apply vendor updates without delay.

MEDIUM Mikrotik CVE published 2017-02-27

CVE-2017-6297

CVE-2017-6297 describes a MikroTik RouterOS L2TP client issue where IPsec encryption may not be enabled after a reboot. In the affected versions identified by NVD, L2TP traffic can be exposed in transit, allowing a man-in-the-middle attacker to view transmitted data unencrypted and potentially obtain the L2TP secret needed to access the server network. The vulnerability was published on 2017-02-27 and is [truncated]