CyberMax
Home › Exploited CVEs

MikroTik known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 MikroTik CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-25), and 0 are known to be used in ransomware campaigns.

MikroTik CVEs added to CISA KEV per year
2021: 1202112022: 1202212026: 320263

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected MikroTik products

RouterOS (5).

All MikroTik CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-67279RouterOSMikrotik RouterOS Improper Enforcement of Behavioral Workflow2026-09-252026-09-281.0%–
CVE-2026-86060RouterOSRouterOS Improper Neutralization of Argument Delimiters in a Command2026-09-102026-09-131.8%–
CVE-2026-67277RouterOSRouterOS Missing Authentication for Critical Function2026-09-102026-09-131.6%–
CVE-2018-7445RouterOSRouterOS Stack-Based Buffer Overflow2022-09-082022-09-2960.8%–
CVE-2018-14847RouterOSRouter OS Directory Traversal2021-12-012022-06-0196.1%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors