Skip to main content
Home Support

Security

Responsible disclosure of discovered vulnerabilities
It is important for us at MikroTik that our customers can feel safe and secure when using our products. We therefore constantly strive to achieve the highest possible security and quality. Despite this, an issue could be discovered, that affects our device security. If you have found such a security flaw, we would like to hear more about it to be able to correct the problem as soon as possible. We are thankful to you for taking the time to report to us weaknesses you discover, as long as you do so with adherence to the following responsible disclosure guidelines.
What you can report?
What you should not report?
If you have found a vulnerability, we kindly ask you to:
We promise you that...

Security Announcements

  • September 2026 vulnerability Sep 3, 2026

    MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.

    This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.

    To give time to update your systems, we are not currently publishing detailed information.

    Your device should already give you the option to upgrade software in the “Check for updates” menu.

    Fix is included in:

    • 7.25 beta 3
    • 7.24.2
    • 7.23.4
    • 6.49.21

    For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade.

    Steps after upgrade

    RouterOS will check if your device has been compromised, and set it to “Flagged” status if it is. This will be written in the “Log” section. If your log has a critical entry saying your device has been Flagged, please follow the instructions in the Flagged status documentation page.

    Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise.

    This article will be updated with more information in due time.


Contact us about vulnerabilities