New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
MikroTik Vulnerability "September 2026"
in Security
Hi all!
For those here who use MikroTik, there is a critical vulnerability... "somewhere". MikroTik doesn't provide any details on https://mikrotik.com/supportsec/september-2026-vulnerability/, nor a CVE from what I could gather, so I propose to call it "fuck" in honors of @rpqu ![]()
Anyway, if you have MikroTiks, you might want to upgrade...
Comments
@angstrom Could you move this to the new "Security" category?
was mikrotik vm affected? they didn't provide any fucking information
The reason: To give time to update your systems, we are not currently publishing detailed information.
given what they link to, you know its really really bad. lol
More details:
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
More CVEs:
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
...so maybe it's a blessing that my RB5009 has been running a broken OpenWRT instance for months after all...
(Thanks for the heads up; I was considering trying RouterOS again but now I'm 100% just gonna reinstall OpenWRT)
OpenWrt is love, although I believe MikroTik is still far more popular especially in corporate environments.