Shanraq.org Shanraq.org
MikroTik Urges RouterOS Update: Which Versions Fix the September Vulnerabilities
IT

MikroTik Urges RouterOS Update: Which Versions Fix the September Vulnerabilities

MikroTik has released fixes for three RouterOS vulnerabilities, while Kazakhstan’s KZ-CERT issued a separate warning. Here are the exact patched versions, how to check the Flagged status, how to restrict SSH, and what to inspect after updating a home or business router.

What the vendor disclosed

MikroTik has released an important RouterOS security update and strongly recommends that all users install it. Fixes are included in 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21, according to the vendor’s official security notice.

The vulnerabilities are collectively known as MikroTrick and tracked as CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. MikroTik is temporarily withholding full technical details to give device owners time to patch. The company says most configurations face no immediate risk, but still recommends upgrading every device.

Kazakhstan’s KZ-CERT also placed a warning about critical RouterOS vulnerabilities in its news feed on September 18.

What router owners should do

  1. Open System → Packages → Check for Updates and choose a patched stable branch supported by the device.
  2. Save both a configuration backup and a settings export before upgrading.
  3. Install the update and reboot the router.
  4. Review the RouterOS log. A critical entry containing Flagged means the built-in check detected signs of compromise.
  5. Even without a Flagged status, inspect users, scripts, scheduled tasks, firewall rules and other configuration. Investigate anything unfamiliar.

Changing a password alone is not a substitute for patching because vulnerable code remains installed. If unknown changes are present, isolate the router, preserve logs for investigation and restore configuration from a known-clean source.

Check SSH separately

The vendor asks users to make sure SSH and other management services are not exposed to untrusted networks. The default configuration normally blocks management access from the internet, but an administrator may have changed that rule.

A safer setup restricts management to trusted IP addresses or makes it available through a VPN such as WireGuard. SSH and administration panels should not be reachable from the entire internet.

Who should prioritize the update

Organizations, internet providers, offices and owners of remotely managed devices should act first. Home users should also patch even if they never changed the defaults. Before starting, check the model and free storage: older hardware may require a specific upgrade path between branches.

The cover is an editorial illustration; the interface shown is not an actual RouterOS screen.

If you have found a mistake or a typo in this article, tell us about it

Comments (0)

No comments yet. Be the first.