Our takeCISA ICSA-26-211-01 warns that MikroTik RouterOS (all versions) lets any low-privilege API user pull the WireGuard private key in plaintext. If you run these routers, rotate the keys immediately and restrict API access.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update all MikroTik RouterOS instances to a version that addresses CVE-2026-14227. If you cannot patch immediately, restrict API access to trusted management networks only.
What this means for you — Lean IT orgs:Check every MikroTik router you use. Update RouterOS to the latest version as soon as possible; until then, turn off API access from the internet.
What this means for you — MSP:Audit all managed MikroTik devices for RouterOS version and API exposure. Apply the fix for CVE-2026-14227 and consider disabling API access on any device that does not require it.
What this means for you — Researcher:MikroTik RouterOS (all versions) leaks the WireGuard private key in plaintext to any authenticated low-privilege API user (CVE-2026-14227).