THREAT OPS › Threat News › MikroTik RouterOS
MikroTik RouterOS
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated tra
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-14227cve
- https://www.cve.org/CVERecord?id=CVE-2026-14227url
- https://mikrotik.com/supporturl
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:Nurl
- https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:Nurl
Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01
Same event, other sources
- MikroTik RouterOScisa_ics · 2026-07-30