Cyber Resilience
← All news
Confirmed

Mikrotik security advisory (AV26-887)

Our takeCCCS reports MikroTik RouterOS flaws under active exploitation. If you run it, update past 6.49.21 / 7.23.4 / 7.24.2 — common edge gear for small networks and anyone self-hosting.
Sources (1)
What this means for you — Security leader:Mikrotik released fixes for RouterOS vulnerabilities under active exploitation (CVE-2026-67276, CVE-2026-67277, CVE-2026-86060). Update immediately to 6.49.21, 7.23.4, 7.24.2 or 7.25 beta 3 if you self-host any Mikrotik devices.
What this means for you — Lean IT orgs:If you run a Mikrotik router or access point, update its RouterOS software right away to one of these versions: 6.49.21, 7.23.4, 7.24.2 or 7.25 beta 3. Attackers are already using these flaws in the wild.
What this means for you — MSP:Audit all client Mikrotik deployments for RouterOS versions prior to 6.49.21, 7.23.4, 7.24.2 or 7.25 beta 3 and push the updates immediately; these CVEs are confirmed under active exploitation.
What this means for you — Researcher:Mikrotik advisory AV26-887 confirms active exploitation of CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 in RouterOS. Fixed in 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3.