An out-of-bounds read vulnerability has been identified in MikroTik RouterOS, in the code that inspects TLS traffic for firewall rules that match TLS connections. A specially crafted packet could allow an attacker to crash the router or disclose a limited amount of memory contents. This issue was reported by Rasmus Moorats and is tracked as CVE-2026-52346.
The vulnerable code is only active on routers that have at least one firewall rule matching TLS connections (the tls-host feature), so devices that don’t use this feature are not affected. In most deployments the router’s firewall drops unsolicited traffic arriving from the internet, which prevents a maliciously crafted packet from reaching this code from the outside. A small number of configurations — such as port forwarding that exposes local services, or permissive firewall settings — could leave the router reachable from the internet. Even then, although the out-of-bounds read itself can be triggered from a distance, actually reading the leaked memory contents requires the ability to create firewall rules on the device, meaning an attacker would already need administrative access. In practice the risk for typical users is low, but upgrading is still strongly recommended.
This issue has been fixed. The fix is included in:
Users are advised to upgrade to one of these versions or any later release.
MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to limit exposure from untrusted networks.
MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.
To give time to update your systems, we are not currently publishing detailed information.
Your device should already give you the option to upgrade software in the “Check for updates” menu.
Fix is included in:
For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade.
Make sure SSH is not open to any untrusted networks. MikroTik default configuration blocks this port from the internet by default, but if you have manually opened this port, make sure only trusted IP can access it, or better yet, use a strong VPN like WireGuard to access your router and do not open any management ports at all.
RouterOS will check if your device has been compromised, and set it to “Flagged” status if it is. This will be written in the “Log” section. If your log has a critical entry saying your device has been Flagged, please follow the instructions in the Flagged status documentation page.
Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise.
Detailed information about these vulnerabilities can be found by the issue codename “MikroTrick” and CVE numbers CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277 as originally reported by CERT.pl
This article will be updated with more information in due time.
Contact us about vulnerabilities