MikroTik known exploited vulnerabilities
CISA lists 5 MikroTik CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-25), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2018-14847 (RouterOS): EPSS 96.1%, added 2021-12-01
- CVE-2018-7445 (RouterOS): EPSS 60.8%, added 2022-09-08
- CVE-2026-86060 (RouterOS): EPSS 1.8%, added 2026-09-10
- CVE-2026-67277 (RouterOS): EPSS 1.6%, added 2026-09-10
- CVE-2026-67279 (RouterOS): EPSS 1.0%, added 2026-09-25
Most affected MikroTik products
RouterOS (5).
All MikroTik CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-67279 | RouterOS | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow | 2026-09-25 | 2026-09-28 | 1.0% | – |
| CVE-2026-86060 | RouterOS | RouterOS Improper Neutralization of Argument Delimiters in a Command | 2026-09-10 | 2026-09-13 | 1.8% | – |
| CVE-2026-67277 | RouterOS | RouterOS Missing Authentication for Critical Function | 2026-09-10 | 2026-09-13 | 1.6% | – |
| CVE-2018-7445 | RouterOS | RouterOS Stack-Based Buffer Overflow | 2022-09-08 | 2022-09-29 | 60.8% | – |
| CVE-2018-14847 | RouterOS | Router OS Directory Traversal | 2021-12-01 | 2022-06-01 | 96.1% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors