Skip to content

MikroTik RouterOS β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NameMikroTik RouterOS
Vendor / Projectmikrotik
Canonical IDmikrotik:routeros
Versioning Schemesemver
CPE Identifierscpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe Release7.25beta3

Documented CVEs

2 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

2 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

2 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to 7.25beta3 to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

1.1 %

β–² +1.1 % over 30d

CISA KEV Activity

2

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10
2026-09-03: CVE: CVE-2026-672772026-09-10: KEV: CVE-2026-86060

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2026-860609.2 (CRITICAL)1.1%CISA KEV< v6.49.21, < v7.23.4, < v7.24.26.49.21, 7.23.4, 7.24.2, 7.25beta3Analysis β†’
CVE-2026-672778.8 (HIGH)0.9%CISA KEV< v6.49.21, < v7.23.4, < v7.24.26.49.21, 7.23.4, 7.24.2, 7.25beta3Analysis β†’

Vulnerabilities impacting MikroTik RouterOS are actively leveraged in real-world intrusion campaigns:


Are you operating MikroTik RouterOS in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: