MikroTik vendor intelligence
MikroTik Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting MikroTik products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 7
- Known exploited vulnerabilities affecting MikroTik products
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- MikroTik KEVs with sensor-observed exploitation activity
The catalog gap matters for MikroTik exposure
Two of the seven exploited MikroTik vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 29% of this vendor portfolio.
- 71%
- Covered by CISA
- 29%
- Beyond CISA
- 1
- Product families
Attested MikroTik vulnerabilities
7 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-67279
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
RouterOS | Confirmed | In CISA | 23 Sep 2026 |
|
CVE-2026-67277
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service |
RouterOS | Confirmed | In CISA | 10 Sep 2026 |
|
CVE-2026-86060
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
RouterOS | Confirmed | In CISA | 10 Sep 2026 |
|
CVE-2026-67276
SSH user impersonation possible in Mikrotik RouterOS |
RouterOS | High | Beyond CISA | 10 Sep 2026 |
|
CVE-2017-20149
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and... |
RouterOS | High | Beyond CISA | 15 Oct 2022 |
|
CVE-2018-14847
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write... |
RouterOS | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2018-7445
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to... |
RouterOS | Confirmed | In CISA | 08 Sep 2022 |
No MikroTik vulnerabilities match this search or filter.
Showing 7 of 7 on this page (7 MikroTik known exploited vulnerabilities).
Recurring weakness patterns
Restriction, limitation, and missing authentication for critical function account for three mapped occurrences across this MikroTik KEV portfolio.
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-306
Missing Authentication for Critical Function
CWE-347
Improper Verification of Cryptographic Signature
CWE-787
Out-of-bounds Write
CWE-841
Improper Enforcement of Behavioral Workflow
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')