Cyber Resilience
← All news

MikroTik RouterOS

Our takeCISA published ICSA-26-211-01 on MikroTik RouterOS: low-privilege API access can extract the WireGuard private key in plaintext (CVE-2026-14227). Patch or rotate keys on every device you manage.
Sources (1)
What this means for you — Security leader:Update all MikroTik RouterOS devices to a version that resolves CVE-2026-14227. If you expose the API, restrict it to trusted management networks only.
What this means for you — Lean IT orgs:Check every MikroTik router you own or rent. Apply the vendor update or disable the API if you cannot patch right away.
What this means for you — MSP:Audit every client MikroTik RouterOS instance for the exposed API. Deploy the patch or disable API access; rekey any affected WireGuard tunnels.
What this means for you — Researcher:MikroTik RouterOS (all versions) leaks the WireGuard private key in plaintext to any authenticated low-privilege API user (CVE-2026-14227).